<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: A note about Symfony security faults</title>
	<atom:link href="http://www.symfonylab.com/a-note-about-symfony-security-faults/feed" rel="self" type="application/rss+xml" />
	<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/</link>
	<description>Everything you wanted to know about Symfony framework but did not know who to ask!</description>
	<pubDate>Fri, 05 Sep 2008 22:43:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Piskvor</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-355</link>
		<dc:creator>Piskvor</dc:creator>
		<pubDate>Mon, 21 Apr 2008 11:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-355</guid>
		<description>Oops, entity filtering ate my post
    robots:       &#60;?php echo((SF_ENVIRONMENT == 'dev') ? 'noindex, nofollow' : 'index,follow'); ?&#62;</description>
		<content:encoded><![CDATA[<p>Oops, entity filtering ate my post<br />
    robots:       &lt;?php echo((SF_ENVIRONMENT == &#8216;dev&#8217;) ? &#8216;noindex, nofollow&#8217; : &#8216;index,follow&#8217;); ?&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Piskvor</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-354</link>
		<dc:creator>Piskvor</dc:creator>
		<pubDate>Mon, 21 Apr 2008 11:44:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-354</guid>
		<description>Also, for the site being spidered by Google: there are META robots tags in default view set to "index, follow."

In case I would accidentaly get my _dev front controller to the test site (God forbid!), I have made a change in my app's view.yml - therefore, polite robots won't index my dev page. It's not a security measure except by obscurity, but better than to have a vulnerability automatically indexed, no?

Here's the change:
    robots:       </description>
		<content:encoded><![CDATA[<p>Also, for the site being spidered by Google: there are META robots tags in default view set to &#8220;index, follow.&#8221;</p>
<p>In case I would accidentaly get my _dev front controller to the test site (God forbid!), I have made a change in my app&#8217;s view.yml - therefore, polite robots won&#8217;t index my dev page. It&#8217;s not a security measure except by obscurity, but better than to have a vulnerability automatically indexed, no?</p>
<p>Here&#8217;s the change:<br />
    robots:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Symfony.es &#187; Blog Archive &#187; Una semana con Symfony #28 (12-20 enero 2008)</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-256</link>
		<dc:creator>Symfony.es &#187; Blog Archive &#187; Una semana con Symfony #28 (12-20 enero 2008)</dc:creator>
		<pubDate>Sun, 03 Feb 2008 11:04:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-256</guid>
		<description>[...] A note about Symfony security faults [...]</description>
		<content:encoded><![CDATA[<p>[...] A note about Symfony security faults [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lukas</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-244</link>
		<dc:creator>Lukas</dc:creator>
		<pubDate>Mon, 21 Jan 2008 10:02:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-244</guid>
		<description>The risk of _dev.php files making it into deployment was a major concern for me from day one. Frameworks should make it hard to fail. Languages should make it hard to fail. PHP does this and symfony for the most part as well.

The good news there is a fix:
http://trac.symfony-project.com/wiki/SecuringDevFrontend

My preferred method "Adapt url/asset helper url generation" will become even easier in symfony 1.1</description>
		<content:encoded><![CDATA[<p>The risk of _dev.php files making it into deployment was a major concern for me from day one. Frameworks should make it hard to fail. Languages should make it hard to fail. PHP does this and symfony for the most part as well.</p>
<p>The good news there is a fix:<br />
<a href="http://trac.symfony-project.com/wiki/SecuringDevFrontend" rel="nofollow">http://trac.symfony-project.com/wiki/SecuringDevFrontend</a></p>
<p>My preferred method &#8220;Adapt url/asset helper url generation&#8221; will become even easier in symfony 1.1</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rpsblog.com &#187; A week of symfony #55 (14-&#38;gt;20 january 2007)</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-243</link>
		<dc:creator>rpsblog.com &#187; A week of symfony #55 (14-&#38;gt;20 january 2007)</dc:creator>
		<pubDate>Sun, 20 Jan 2008 23:00:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-243</guid>
		<description>[...] A note about Symfony security faults [...]</description>
		<content:encoded><![CDATA[<p>[...] A note about Symfony security faults [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Youpi</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-240</link>
		<dc:creator>Youpi</dc:creator>
		<pubDate>Sat, 19 Jan 2008 09:29:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-240</guid>
		<description>What's unfair is to publish the urls where the dev front controllers are publicly available. this is a major security hole as it shows db queries, server env vars and so on.

You encourage exploits attempts and script kiddies challenges. That's unfair, IMHO.</description>
		<content:encoded><![CDATA[<p>What&#8217;s unfair is to publish the urls where the dev front controllers are publicly available. this is a major security hole as it shows db queries, server env vars and so on.</p>
<p>You encourage exploits attempts and script kiddies challenges. That&#8217;s unfair, IMHO.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Teal</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-239</link>
		<dc:creator>Teal</dc:creator>
		<pubDate>Sat, 19 Jan 2008 08:19:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-239</guid>
		<description>It looks like 3 of 4 your examples is made by same person. At least they are on same host.

Anyway good points which hopelly are obvious most of us...</description>
		<content:encoded><![CDATA[<p>It looks like 3 of 4 your examples is made by same person. At least they are on same host.</p>
<p>Anyway good points which hopelly are obvious most of us&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stefan</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-238</link>
		<dc:creator>stefan</dc:creator>
		<pubDate>Fri, 18 Jan 2008 21:51:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-238</guid>
		<description>I actually fell for the _dev problem as well. And actually, I still forgot to add it to the rsync_exclude list. need to do that.</description>
		<content:encoded><![CDATA[<p>I actually fell for the _dev problem as well. And actually, I still forgot to add it to the rsync_exclude list. need to do that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-237</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 18 Jan 2008 17:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-237</guid>
		<description>What exactly is not fair?</description>
		<content:encoded><![CDATA[<p>What exactly is not fair?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Youpi</title>
		<link>http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-236</link>
		<dc:creator>Youpi</dc:creator>
		<pubDate>Fri, 18 Jan 2008 17:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.symfonylab.com/a-note-about-symfony-security-faults/#comment-236</guid>
		<description>Right, very. But that's not fair with people having the problems you describe.</description>
		<content:encoded><![CDATA[<p>Right, very. But that&#8217;s not fair with people having the problems you describe.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
