Every other tech, it's complicated servers or complicated billing, not to mention depencies and build tools.
thats why php
Every other tech, it's complicated servers or complicated billing, not to mention depencies and build tools.
thats why php
The server software reads the config file and then decides if the folder can be accessed externally or not.
It has nothing to do with PHP what framework or any other language you are running.
Yup. That's why I am saying that in the past .htaccess used to be used, but modern php frameworks no longer rely on it. Poor phrasing on my end.
Every other language acts as its own web server which wouldn't even be capable of serving files even if you tried; the only thing it does is respond to web routes defined by the application.
This eliminates a whole chunk of security issues, from the one described above to malicious file uploads (PHP is probably the only language where a malicious file upload leads to RCE by default - other languages could happily accept and serve the malicious file back but wouldn't execute it).
A non issue though after 2-3 days of working with this approach. All modern PHP frameworks have a so called front controller (an index.php file) that loads what it requires from ../ after, ideally, properly validating the request to avoid issues.
Tell that to all the people with bleeding feet.
If I had to guess, this person committed their .env file in some repo and pushed that up, and that become available because the server was misconfigured.
For other servers (such as, say, Jetty), config files like that won't get exposed like that unless you're very obviously placing your config files in a public resource folder.
The only way to avoid to have the server open only to you till everything is tied down right and the backend is ready to face the world.
To rely upon being quicker on the draw than the bots is quite courageous.
When you extrapolate that to modern tech, you could create a shared hoster with a configured reverse proxy and per customer docker images.
But that is so much expensive to build, operate and bill than an apache. And looks very close to AWS and friends.
Keep a shared host secure, PHP or something else was not an easy task, most people installed unsecure versions or misconfigure something.
Also it was a pain to support PHP versions after EOL (yes, money), and multiple versions .
Not with CGI.
Thanks to cPanel (written in Perl) this make life easier for developers to set up websites and skipped the ceremony but why is cPanel written in Perl instead of PHP?
But Go language has it own security implementations which are more secure and easier to deploy as a static binary. I did tried to write entire Go app using only built-in or some dev use Chi for routing. I didn't have to install Go runtime on VPS that you need for PHP.
Go built-in HTML template is quite secure, rare seen some fix to html/template make it easier to deploy new app, but our website has evolved with Astro web framework that require NodeJS since none of the server side language can solve client-side issues.