and next to that, it is the servers admins responsibility to secure the server. You say html can crash a server, indeed but PHP, CGI are a lot worse and easier to crack servers.
This is the major head ache of every server admin, not only to protect against those wanting to kill your server, but also against those starting to code and 'by accident' kill your server. Not every server kill is because someone wanted it. I saw in the past simple scripts overload a server to crash just by sending mysql in a loop.
No single script is perfect and the more options scripts give, the harder it will be to keep a server secure. That's the price to pay for trying to give better and better programs.
Don't only blame coders, I saw enough servers ran by youngster knowing hardly a line of Linux to host accounts. Today it is easy, a few $, a server package that manages all and they think all is fine... yeah... except that keeping a server secure, is almost a full time job.
I'm sure most coders learn as they go and even experienced coders still find new loopholes.. same for server admins, what seems perfect today might be... hopeless in a few weeks.
Instead just saying it is bad, maybe contact her and share your knowledge, findings, who knows you both can even find a solution to make it better. We all will be better with it.
|