Every programming language has holes, its just that with PHP the attack surface is much larger, so i guess people find more holes, etc..
Are you advocating “security by obscurity”?
Every programming language has holes, its just that with PHP the attack surface is much larger, so i guess people find more holes, etc..
Are you advocating “security by obscurity”?
Information-gathering is a common early step in any attack against a system; knowing the language & libraries involved (especially their versions) allows you to search for any existing CVEs that apply.
> Are you advocating “security by obscurity”?
I don't think OP was implying that security by obscurity alone is sufficient, just that it's unwise to advertise information that's not relevant to end users, that could help would-be attackers.
Back in the day (!), server software used to honestly respond with things like the software name and exact version number it was running.
Naturally, that meant scanning for vulnerabilities was a lot easier than it needed to be.
There's also the way of most using runtimes/libraries that (constantly) have CVEs in them; and understanding why it is that these languages have CVEs in the first place (see my comment on "eval()").
These things are not so easy, say, with a C++/Rust/Go app. Or even in most JVM configurations. JS has similar issues, that Deno is trying to mitigate to some extend.
obscurity is absolutely part of good security practice, as long as it's not all you're relying on.