Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PHP sites will have a hell of a lot more of them, though. You're not shielded against CSRF, XSS or SQL injection attacks unless you use a framework - at which point you're back to being a programmer with no "empowered amateur" in sight...


Hell, for most of then you aren't even protected against remote code execution. Google for "PHP arbitrary script execution" and weep.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: