Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

Rebellion lay in his way, and he found it. -- William Shakespeare, "Henry IV"


comp / comp.os.linux.advocacy / Crap Language Running On Crap OS = Double Sadness

SubjectAuthor
* Crap Language Running On Crap OS = Double SadnessLawrence D'Oliveiro
`* Re: Crap Language Running On Crap OS = Double SadnessChris Ahlstrom
 +* Re: Crap Language Running On Crap OS = Double SadnessJoel
 |`* Re: Crap Language Running On Crap OS = Double Sadnessrbowman
 | `- Re: Crap Language Running On Crap OS = Double SadnessLawrence D'Oliveiro
 `* Re: Crap Language Running On Crap OS = Double Sadnessrbowman
  `- Re: Crap Language Running On Crap OS = Double SadnessLawrence D'Oliveiro

1
Subject: Crap Language Running On Crap OS = Double Sadness
From: Lawrence D'Oliv
Newsgroups: comp.os.linux.advocacy
Organization: A noiseless patient Spider
Date: Sat, 8 Jun 2024 00:23 UTC
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: ldo@nz.invalid (Lawrence D'Oliveiro)
Newsgroups: comp.os.linux.advocacy
Subject: Crap Language Running On Crap OS = Double Sadness
Date: Sat, 8 Jun 2024 00:23:35 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 7
Message-ID: <v408a6$29nhl$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 08 Jun 2024 02:23:35 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="41ddd3104c6f00811ea81eed5288e7ff";
logging-data="2416181"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19imADciT1ntLQwDZnnmWU9"
User-Agent: Pan/0.158 (Avdiivka; )
Cancel-Lock: sha1:waAdh4rwOPZl/dm32jpE2uOnxUM=
View all headers

PHP is bad enough as a language, and Windows is bad enough as an OS.
But put the two together, and you can get some real Greek tragedy
going. Look at this lovely combination where an OS is trying to be
helpful with substituting characters it doesn’t understand, together
with a language that has its own helpfulness, leading to a massive
security hole
<https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/>.

Subject: Re: Crap Language Running On Crap OS = Double Sadness
From: Chris Ahlstrom
Newsgroups: comp.os.linux.advocacy
Organization: None
Date: Sat, 8 Jun 2024 10:49 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: OFeem1987@teleworm.us (Chris Ahlstrom)
Newsgroups: comp.os.linux.advocacy
Subject: Re: Crap Language Running On Crap OS = Double Sadness
Date: Sat, 8 Jun 2024 06:49:16 -0400
Organization: None
Lines: 34
Message-ID: <v41cvc$2ipqm$2@dont-email.me>
References: <v408a6$29nhl$2@dont-email.me>
Reply-To: OFeem1987@teleworm.us
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 08 Jun 2024 12:49:17 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="0bfa1d85c1d2a92ca4ab17ef3136bc5f";
logging-data="2713430"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/L4pv4B3kspNZCSTrLNefA"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:1yPLmRQ7tNn0CC0bSxZCkrhbxHs=
X-User-Agent: Microsoft Outl00k, Usenet K00k Editions
X-Mutt: The most widely-used MUA
X-Slrn: Why use anything else?
View all headers

Lawrence D'Oliveiro wrote this copyrighted missive and expects royalties:

> PHP is bad enough as a language, and Windows is bad enough as an OS.
> But put the two together, and you can get some real Greek tragedy
> going. Look at this lovely combination where an OS is trying to be
> helpful with substituting characters it doesn’t understand, together
> with a language that has its own helpfulness, leading to a massive
> security hole
>
> <https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/>.

I wrote some PHP code once, long ago. Weird, uh, "language".

Anyway, from the article:

CVE-2024-4577, as the vulnerability is tracked, stems from errors in the
way PHP converts unicode characters into ASCII. A feature built into
Windows known as Best Fit allows attackers to use a technique known as
argument injection to pass user-supplied input into commands executed by an
application, in this case, PHP. Exploits allow attackers to bypass
CVE-2012-1823, a critical code execution vulnerability patched in PHP in
2012.

“While implementing PHP, the team did not notice the Best-Fit feature of
encoding conversion within the Windows operating system,” researchers with
Devcore, the security firm that discovered CVE-2024-4577, wrote. “This
oversight allows unauthenticated attackers to bypass the previous
protection of CVE-2012-1823 by specific character sequences. Arbitrary code
can be executed on remote PHP servers through the argument injection
attack.”

--
A man was reading The Canterbury Tales one Saturday morning, when his
wife asked "What have you got there?" Replied he, "Just my cup and Chaucer."

Subject: Re: Crap Language Running On Crap OS = Double Sadness
From: Joel
Newsgroups: comp.os.linux.advocacy
Date: Sat, 8 Jun 2024 11:25 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!border-2.nntp.ord.giganews.com!border-1.nntp.ord.giganews.com!nntp.giganews.com!news-out.netnews.com!postmaster.netnews.com!us11.netnews.com!not-for-mail
X-Trace: DXC=91kGSdT@>KbO5da<66@17mHWonT5<]0TmdjI?Uho:XeklL51CP6LDLl95GMl]75=8aXKGVB;YbeAiWim7Li1M05nbA4<PQUTBUkFeF>2oJX=@`
X-Complaints-To: support@blocknews.net
From: joelcrump@gmail.com (Joel)
Newsgroups: comp.os.linux.advocacy
Subject: Re: Crap Language Running On Crap OS = Double Sadness
Date: Sat, 08 Jun 2024 07:25:27 -0400
Message-ID: <jmf86jtkd5bc4u3k0f9non3q8em8qer09g@4ax.com>
References: <v408a6$29nhl$2@dont-email.me> <v41cvc$2ipqm$2@dont-email.me>
User-Agent: ForteAgent/8.00.32.1272
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
OS: Linux Mint 21.3 Cinnamon, with Wine 9.0 for WinAPI
Lines: 58
NNTP-Posting-Host: 127.0.0.1
X-Trace: 1717845927 reader.netnews.com 2363148 127.0.0.1:37277
View all headers

Chris Ahlstrom <OFeem1987@teleworm.us> wrote:
>Lawrence D'Oliveiro wrote this copyrighted missive and expects royalties:
>
>> PHP is bad enough as a language, and Windows is bad enough as an OS.
>> But put the two together, and you can get some real Greek tragedy
>> going. Look at this lovely combination where an OS is trying to be
>> helpful with substituting characters it doesn’t understand, together
>> with a language that has its own helpfulness, leading to a massive
>> security hole
>>
>> <https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/>.
>
>I wrote some PHP code once, long ago. Weird, uh, "language".
>
>Anyway, from the article:
>
> CVE-2024-4577, as the vulnerability is tracked, stems from errors in the
> way PHP converts unicode characters into ASCII. A feature built into
> Windows known as Best Fit allows attackers to use a technique known as
> argument injection to pass user-supplied input into commands executed by an
> application, in this case, PHP. Exploits allow attackers to bypass
> CVE-2012-1823, a critical code execution vulnerability patched in PHP in
> 2012.
>
> “While implementing PHP, the team did not notice the Best-Fit feature of
> encoding conversion within the Windows operating system,” researchers with
> Devcore, the security firm that discovered CVE-2024-4577, wrote. “This
> oversight allows unauthenticated attackers to bypass the previous
> protection of CVE-2012-1823 by specific character sequences. Arbitrary code
> can be executed on remote PHP servers through the argument injection
> attack.”

Clearly, this is the result of M$'s obsession with, essentially,
bloat. It's like they would say about "liberals", never a tax
increase they didn't like (not that I'm against higher taxes, but it
is a sort of analogy), Microsoft will add any "feature" imaginable, so
we end up with this new AI hardware requirement, as if intelligent
people would need that, good lord, I had only begun to sense how
doomed my upgrade path was with Win11. Turns out, the sooner I
switched back to Linux, the better, and there is *NO* turning back,
for damn sure.

--
Joel W. Crump

Amendment XIV
Section 1.

[...] No state shall make or enforce any law which shall
abridge the privileges or immunities of citizens of the
United States; nor shall any state deprive any person of
life, liberty, or property, without due process of law;
nor deny to any person within its jurisdiction the equal
protection of the laws.

Dobbs rewrites this, it is invalid precedent. States are
liable for denying needed abortions, e.g. TX.

Subject: Re: Crap Language Running On Crap OS = Double Sadness
From: rbowman
Newsgroups: comp.os.linux.advocacy
Date: Sat, 8 Jun 2024 19:26 UTC
References: 1 2
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: bowman@montana.com (rbowman)
Newsgroups: comp.os.linux.advocacy
Subject: Re: Crap Language Running On Crap OS = Double Sadness
Date: 8 Jun 2024 19:26:30 GMT
Lines: 10
Message-ID: <lcjpj6F8ugpU3@mid.individual.net>
References: <v408a6$29nhl$2@dont-email.me> <v41cvc$2ipqm$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net J87C7q00PW+4BW1zT1WQaQg6f66iFPLHatAfA7HBZgpXgTL0GR
Cancel-Lock: sha1:tlBPa/BS4a9KVja7/mxH3HTdGw8= sha256:XIHsgcF4Z/4JHmHmg0u+Q7Sk6uOHagny97VTj0UEOEA=
User-Agent: Pan/0.149 (Bellevue; 4c157ba)
View all headers

On Sat, 8 Jun 2024 06:49:16 -0400, Chris Ahlstrom wrote:

> I wrote some PHP code once, long ago. Weird, uh, "language".

We have one programmer who loves PHP, generally some obsolete version. I
always expected a cage match between him and our QA head. She had been a
web designer and could make an acceptable looking page with css. At least
with what he produced the crap you got wasn't susceptible to styling and
like most programmers he was not any good at UX.

Subject: Re: Crap Language Running On Crap OS = Double Sadness
From: rbowman
Newsgroups: comp.os.linux.advocacy
Date: Sat, 8 Jun 2024 19:41 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.nobody.at!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: bowman@montana.com (rbowman)
Newsgroups: comp.os.linux.advocacy
Subject: Re: Crap Language Running On Crap OS = Double Sadness
Date: 8 Jun 2024 19:41:31 GMT
Lines: 32
Message-ID: <lcjqfbF8ugpU4@mid.individual.net>
References: <v408a6$29nhl$2@dont-email.me> <v41cvc$2ipqm$2@dont-email.me>
<jmf86jtkd5bc4u3k0f9non3q8em8qer09g@4ax.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net pZrEHXOpRW4mcYkeXDVEeg8YqHZnPJgtDSdxn/GTKmAt+L0aHz
Cancel-Lock: sha1:PyG2Ry312kJ9JxCSwsJbaJPzOhM= sha256:72K3jRLSLyy9K9nGyKK3huKGYxsYysKjtUvb48bXvfg=
User-Agent: Pan/0.149 (Bellevue; 4c157ba)
View all headers

On Sat, 08 Jun 2024 07:25:27 -0400, Joel wrote:

> Clearly, this is the result of M$'s obsession with, essentially, bloat.
> It's like they would say about "liberals", never a tax increase they
> didn't like (not that I'm against higher taxes, but it is a sort of
> analogy), Microsoft will add any "feature" imaginable, so we end up with
> this new AI hardware requirement, as if intelligent people would need
> that, good lord, I had only begun to sense how doomed my upgrade path
> was with Win11. Turns out, the sooner I switched back to Linux, the
> better, and there is *NO* turning back, for damn sure.

I think the automotive industry has changed or maybe it's just I can't
tell cars apart anymore. When I was a kid, any self-respecting male could
tell a '56 Chevy from a '57 Chevy from a block away, let alone a '57 Ford
We were also attuned to how many fake portholes a Buick had. That
apparently hasn't gone away.

https://www.macsmotorcitygarage.com/buick-portholes-a-10-minute-history/

Anyway the engines and running gear seldom changed. It was just sheet
metal to generate new sales as people tried to keep up with the Joneses.
It also helped that cars were pretty much burned out at 75,000 miles.

Anyway, MS, and to a good extent the Linux DE people, are always looking
for something new and different, not necessarily any better. Right now the
AI race is the driving force. Manufacturers are hoping to drive up lagging
sales, and MS is trying to stay ahead of Google and Apple. New sheet
metal.

Some investors are starting to bet the AI craze will collapse. I tend to
agree since the prior iterations were always oversold and collapsed.

Subject: Re: Crap Language Running On Crap OS = Double Sadness
From: Lawrence D'Oliv
Newsgroups: comp.os.linux.advocacy
Organization: A noiseless patient Spider
Date: Sun, 9 Jun 2024 00:01 UTC
References: 1 2 3
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: ldo@nz.invalid (Lawrence D'Oliveiro)
Newsgroups: comp.os.linux.advocacy
Subject: Re: Crap Language Running On Crap OS = Double Sadness
Date: Sun, 9 Jun 2024 00:01:23 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 16
Message-ID: <v42rci$2u4lh$3@dont-email.me>
References: <v408a6$29nhl$2@dont-email.me> <v41cvc$2ipqm$2@dont-email.me>
<lcjpj6F8ugpU3@mid.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 09 Jun 2024 02:01:23 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="e98d6c6f2f9dfe52aa544b0d04bc91ad";
logging-data="3084977"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+lWALFmdMld2+YVR0Aty9j"
User-Agent: Pan/0.158 (Avdiivka; )
Cancel-Lock: sha1:yqIT/v9DI2YlMz8426eV0uXjq9g=
View all headers

On 8 Jun 2024 19:26:30 GMT, rbowman wrote:

> At least with what he produced the crap you got wasn't susceptible to
> styling and like most programmers he was not any good at UX.

I took over development of a significant-sized PHP app that was written
for a client by a previous freelancer.

It had stylesheets in it to begin with, so I suppose that’s something.

I have fixed various brain-deadness in the code (e.g. the usual database
sloppiness) as I have had to touch parts of it to add features, fix bugs
etc.

I like to go back to Python after a PHP session to ... kind of ... get the
taste out of my mouth ...

Subject: Re: Crap Language Running On Crap OS = Double Sadness
From: Lawrence D'Oliv
Newsgroups: comp.os.linux.advocacy
Organization: A noiseless patient Spider
Date: Sun, 9 Jun 2024 00:03 UTC
References: 1 2 3 4
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: ldo@nz.invalid (Lawrence D'Oliveiro)
Newsgroups: comp.os.linux.advocacy
Subject: Re: Crap Language Running On Crap OS = Double Sadness
Date: Sun, 9 Jun 2024 00:03:35 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 7
Message-ID: <v42rgm$2u4lh$4@dont-email.me>
References: <v408a6$29nhl$2@dont-email.me> <v41cvc$2ipqm$2@dont-email.me>
<jmf86jtkd5bc4u3k0f9non3q8em8qer09g@4ax.com>
<lcjqfbF8ugpU4@mid.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 09 Jun 2024 02:03:35 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="e98d6c6f2f9dfe52aa544b0d04bc91ad";
logging-data="3084977"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19Az4wkpUg//wNr2jwBy21R"
User-Agent: Pan/0.158 (Avdiivka; )
Cancel-Lock: sha1:kzAFhqYzKf9b4JdqgJzAIruSQ0Y=
View all headers

On 8 Jun 2024 19:41:31 GMT, rbowman wrote:

> Anyway, MS, and to a good extent the Linux DE people, are always looking
> for something new and different, not necessarily any better.

Spot the difference: One of those wants to give you more choice, the other
wants to take it away.

1

rocksolid light 0.9.8
clearnet tor