<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Vulnerability affects PHP XML-RPC library</title>
	<atom:link href="http://www.sitepoint.com/blogs/2005/07/06/vulnerability-affects-php-xml-rpc-library/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sitepoint.com/blogs/2005/07/06/vulnerability-affects-php-xml-rpc-library/</link>
	<description>News, opinion, and fresh thinking for web developers and designers. The official podcast of sitepoint.com.</description>
	<lastBuildDate>Mon, 23 Nov 2009 01:39:24 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nico Edtinger</title>
		<link>http://www.sitepoint.com/blogs/2005/07/06/vulnerability-affects-php-xml-rpc-library/comment-page-1/#comment-2239</link>
		<dc:creator>Nico Edtinger</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">2080789859#comment-2239</guid>
		<description>&lt;p&gt;May I take the quote out of the article &quot;Eval i dead&quot; from February (!): Rasmus: &quot;If eval() is the answer, you&#039;re almost certainly asking the wrong question.&quot;&lt;/p&gt;

&lt;p&gt;It&#039;s here: http://www.sitepoint.com/blog-post-view.php?id=238381&lt;/p&gt;

&lt;p&gt;So we already knew it before. And still they thought it would be easier to use eval() to decode. BTW both libs seem to come from the same code.&lt;/p&gt;

&lt;p&gt;The solution is simple. Don&#039;t use code that uses eval und code you don&#039;t know exactly. If a string is generated from user input you can never know what the string&#039;ll look like. Thus no one should use both libs as long as they only code around the problem instead of finding a replacment for the eval()&lt;/p&gt;

&lt;p&gt;b4n&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>May I take the quote out of the article &#8220;Eval i dead&#8221; from February (!): Rasmus: &#8220;If eval() is the answer, you&#8217;re almost certainly asking the wrong question.&#8221;</p>
<p>It&#8217;s here: <a href="http://www.sitepoint.com/blog-post-view.php?id=238381" rel="nofollow">http://www.sitepoint.com/blog-post-view.php?id=238381</a></p>
<p>So we already knew it before. And still they thought it would be easier to use eval() to decode. BTW both libs seem to come from the same code.</p>
<p>The solution is simple. Don&#8217;t use code that uses eval und code you don&#8217;t know exactly. If a string is generated from user input you can never know what the string&#8217;ll look like. Thus no one should use both libs as long as they only code around the problem instead of finding a replacment for the eval()</p>
<p>b4n</p>]]></content:encoded>
	</item>
	<item>
		<title>By: DaisyChain</title>
		<link>http://www.sitepoint.com/blogs/2005/07/06/vulnerability-affects-php-xml-rpc-library/comment-page-1/#comment-2240</link>
		<dc:creator>DaisyChain</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">2080789859#comment-2240</guid>
		<description>&lt;p&gt;The new book sounds exiting!! When will it be released and are you able to say yet what topics its going to cover? I&#039;m keen to start learning about pratical applications of XML.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>The new book sounds exiting!! When will it be released and are you able to say yet what topics its going to cover? I&#8217;m keen to start learning about pratical applications of XML.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Clenard</title>
		<link>http://www.sitepoint.com/blogs/2005/07/06/vulnerability-affects-php-xml-rpc-library/comment-page-1/#comment-2241</link>
		<dc:creator>Clenard</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">2080789859#comment-2241</guid>
		<description>&lt;p&gt;Looking forward to this new book!&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Looking forward to this new book!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Gaetano Giunta</title>
		<link>http://www.sitepoint.com/blogs/2005/07/06/vulnerability-affects-php-xml-rpc-library/comment-page-1/#comment-2242</link>
		<dc:creator>Gaetano Giunta</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">2080789859#comment-2242</guid>
		<description>&lt;p&gt;May I only point out that the code in question dates circa 1999, long before the php core team had even dreamed about &#039;register_blobals=BAD&#039;.&lt;/p&gt;

&lt;p&gt;Everybody is tighter on security as of 2005.&lt;/p&gt;

&lt;p&gt;The only strange thing is nobody had ever found the breach before, given the wide exposure of the libs...&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>May I only point out that the code in question dates circa 1999, long before the php core team had even dreamed about &#8216;register_blobals=BAD&#8217;.</p>
<p>Everybody is tighter on security as of 2005.</p>
<p>The only strange thing is nobody had ever found the breach before, given the wide exposure of the libs&#8230;</p>]]></content:encoded>
	</item>
</channel>
</rss>
