Stories
Slash Boxes
Comments

SoylentNews is people

posted by Blackmoore on Wednesday January 07 2015, @10:02PM   Printer-friendly
from the all-your-base dept.

Over three-quarters of all installs are insecure, research shows

The Register -Want to have your server pwned? Easy: Run PHP

More than 78 per cent of all PHP installations are running with at least one known security vulnerability, a researcher has found.

Google developer advocate Anthony Ferrara reached this unpleasant conclusion by correlating statistics from web survey site W3Techs with lists of known vulnerabilities in various versions of PHP.

What he found is that many, many PHP-powered websites are using insecure versions of the interpreter – so much so that it's actually easier to find an insecure PHP setup on the internet than a secure one.

"This is absolutely and unequivocally pathetic," Ferrara wrote.

The two most popular PHP releases, according to W3Techs' statistics, were versions 5.2.17 and 5.3.29. Together, they accounted for 24 per cent of the total – and both are insecure.

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by DrMag on Wednesday January 07 2015, @11:03PM

    by DrMag (1860) on Wednesday January 07 2015, @11:03PM (#132747)

    Checking my server (hosted at Arvixe), I see that the default php is 5.3.28, which apparently is considered by TFA to be insecure. However, the publicly accessible website is running 5.4.27, because it's built into the installation of Drupal powering the website. (Also insecure, it turns out.)

    Probably most websites aren't built by hand, but from something like Drupal or Wordpress or Dokuwiki or somesuch. So even if you push your host provider to update php, it may not make a difference because the other software has a different version built in.

    Any advice on how to sort all of that out and ensure that every public face is secure?

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 0) by Anonymous Coward on Wednesday January 07 2015, @11:07PM

    by Anonymous Coward on Wednesday January 07 2015, @11:07PM (#132749)

    Any advice on how to sort all of that out and ensure that every public face is secure?

    Burqa.