Baph
30-03-07, 08:13 AM
Hmmm PHP Exec() being on is bad, mkay.
In itself, I disagree. If you aren't 10000000% sure what the source code does, you're right, it can be bad.
If it's accepting input from a visitor to the website (even just as params to a program), it's potentially devastating.
I've just had a look on the menalto website, and please please please DONT run that software. Not only does it require exec() but also it requires magic_quotes_gpc off!!
This is asking for someone to take your part of the server over! It's the equivalent of leaving your bike keys in the ignition, helmet, gloves, jacket & trousers on the bike!!!
In itself, I disagree. If you aren't 10000000% sure what the source code does, you're right, it can be bad.
If it's accepting input from a visitor to the website (even just as params to a program), it's potentially devastating.
I've just had a look on the menalto website, and please please please DONT run that software. Not only does it require exec() but also it requires magic_quotes_gpc off!!
This is asking for someone to take your part of the server over! It's the equivalent of leaving your bike keys in the ignition, helmet, gloves, jacket & trousers on the bike!!!