<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Server Hacked Thanks to Insecure PHP Script</title>
	<atom:link href="http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/</link>
	<description>Website Promotion, Generating Revenue, Website Management</description>
	<lastBuildDate>Sat, 28 Feb 2026 22:09:57 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.8.41</generator>
	<item>
		<title>By: Hamid</title>
		<link>http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/#comment-48170</link>
		<dc:creator><![CDATA[Hamid]]></dc:creator>
		<pubDate>Sat, 18 Jun 2011 12:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.websitepublisher.net/blog/?p=205#comment-48170</guid>
		<description><![CDATA[I had similar experience with same company VALUE ON WEB and selected them for same reasons. I ended us losing a lot of money and when tried to have code reviewed by new company got this response - 
&quot;Hello Hamid, Thanks for sending over the files, unfortunately the code is awful. You have about 300 PHP files which all have html and php code together. Not even the slightest separation has been attempted. Also, just a warning, the project has a big security risk. All queries on the database are not protected against even the most basic attacks like sql injections. From what we could see Zend has not been used at all. Given the current status we can&#039;t take over the existing code. Let me know your thoughts. Best wishes, Paul&quot;]]></description>
		<content:encoded><![CDATA[<p>I had similar experience with same company VALUE ON WEB and selected them for same reasons. I ended us losing a lot of money and when tried to have code reviewed by new company got this response &#8211;<br />
&#8220;Hello Hamid, Thanks for sending over the files, unfortunately the code is awful. You have about 300 PHP files which all have html and php code together. Not even the slightest separation has been attempted. Also, just a warning, the project has a big security risk. All queries on the database are not protected against even the most basic attacks like sql injections. From what we could see Zend has not been used at all. Given the current status we can&#8217;t take over the existing code. Let me know your thoughts. Best wishes, Paul&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Demaio</title>
		<link>http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/#comment-44677</link>
		<dc:creator><![CDATA[Marco Demaio]]></dc:creator>
		<pubDate>Wed, 15 Dec 2010 20:27:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.websitepublisher.net/blog/?p=205#comment-44677</guid>
		<description><![CDATA[the truth is that security is not a good marketing word, people expect security as normal part of the job, like when at the supermarket they buy a can of beans they expect  not to find inside a moldy one so they just look at the color of the sticker on the can and at the advertisement they saw on tv show. But good programmers are usually not good in marketing, and beside you not many people are willing to pay so many bucks for programmers.]]></description>
		<content:encoded><![CDATA[<p>the truth is that security is not a good marketing word, people expect security as normal part of the job, like when at the supermarket they buy a can of beans they expect  not to find inside a moldy one so they just look at the color of the sticker on the can and at the advertisement they saw on tv show. But good programmers are usually not good in marketing, and beside you not many people are willing to pay so many bucks for programmers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Bridgeman</title>
		<link>http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/#comment-43870</link>
		<dc:creator><![CDATA[Mark Bridgeman]]></dc:creator>
		<pubDate>Fri, 12 Nov 2010 13:27:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.websitepublisher.net/blog/?p=205#comment-43870</guid>
		<description><![CDATA[I fully agree with the above, as I professional web builder I have had servers hacked in the past when I&#039;ve taken over someone else&#039;s website as the customer was unhappy with the previous company.  I&#039;m older and wiser now and understand that I should not take it on face value that another companies code is ok simply because they are &#039;professionals&#039;.  I&#039;ve learned that they might be competent, but &#039;competent&#039; and &#039;professional&#039; are not the same thing.  Furthermore there is nothing worse than picking through someone elses unfamiliar code...]]></description>
		<content:encoded><![CDATA[<p>I fully agree with the above, as I professional web builder I have had servers hacked in the past when I&#8217;ve taken over someone else&#8217;s website as the customer was unhappy with the previous company.  I&#8217;m older and wiser now and understand that I should not take it on face value that another companies code is ok simply because they are &#8216;professionals&#8217;.  I&#8217;ve learned that they might be competent, but &#8216;competent&#8217; and &#8216;professional&#8217; are not the same thing.  Furthermore there is nothing worse than picking through someone elses unfamiliar code&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karen Mae Farro</title>
		<link>http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/#comment-42863</link>
		<dc:creator><![CDATA[Karen Mae Farro]]></dc:creator>
		<pubDate>Tue, 28 Sep 2010 16:07:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.websitepublisher.net/blog/?p=205#comment-42863</guid>
		<description><![CDATA[The success of a certain business depends not only to the manager but also to the staff. It is just so annoying sometimes to have such an irresponsible employee which is not dedicated or serious with work. What I do, actually, is to base their income on their output. That way they are motivated to work hard and better.]]></description>
		<content:encoded><![CDATA[<p>The success of a certain business depends not only to the manager but also to the staff. It is just so annoying sometimes to have such an irresponsible employee which is not dedicated or serious with work. What I do, actually, is to base their income on their output. That way they are motivated to work hard and better.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wesley</title>
		<link>http://www.websitepublisher.net/blog/2010/09/07/server-hacked-thanks-to-insecure-php-script/#comment-42212</link>
		<dc:creator><![CDATA[wesley]]></dc:creator>
		<pubDate>Tue, 07 Sep 2010 17:34:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.websitepublisher.net/blog/?p=205#comment-42212</guid>
		<description><![CDATA[You should require all projects to be done in some sort of PHP framework, something like kohana or yii. In my experience that will get rid of a lot of the crap firms... Plus, these frameworks have several security standards built in (file uploading, sql escaping, etc..)]]></description>
		<content:encoded><![CDATA[<p>You should require all projects to be done in some sort of PHP framework, something like kohana or yii. In my experience that will get rid of a lot of the crap firms&#8230; Plus, these frameworks have several security standards built in (file uploading, sql escaping, etc..)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
