OpenWeb - 3.0.2configured Apache 2 Secure Web Server |
|
||||||||||||||||
|
|||||||||||||||||
Feedback Summary:
| This Version: | |||||
| Overall Rating: | Not rated (0.0) | Features: | Not rated (0.0) | Support: | Not rated (0.0) |
| Ease of Use: | Not rated (0.0) | Quality / Stability: | Not rated (0.0) | Price: | Not rated (0.0) |
Key to Types of Feedback:
Reviews
Troubleshooting
Usage Tips
Developer Notes
Commentary
Featured Reviews
be aware - Version: 3.0.2, 11/8/2005 10:53PM PST
InvalidResponse
first off.. all of this is free software. and while the author may offer pre-compiled, pre-configured applications, they are not "easy-to-use". there are serious security ramifications in passing off these installers as "simple and easy to use". For example: the execute_program() function that seems to be built into PHP, is a VERY serious security concern. What makes it more concerning is that the author quotes the start tag as <php? repeatedly, not only is this wrong, but illustrates their lack of basic comprehension of the language. They state that it can be "magically" called from another html page, which can only be done as documented with register_globals enabled, which is another very serious security concern. Bundle the two concerns together with an amateur target market and you have a very good chance of an attacker executing system commands on your computer.
To summarize my concerns, this should not be considered a "one click" solution for amateurs. It's a reckless statement. 3 of the applications bundled with this software are very well known to have numerous and frequent security holes (exploits) and are often primary targets of your average script kiddie (hacker). I can almost guarantee that any user installing this package without a decent amount of understanding of what they're doing will be hacked, may have their system compromised, and may potentially seek damages from the author.
The potential license violations are another story. I'm not a lawyer, so I won't comment.
To summarize my concerns, this should not be considered a "one click" solution for amateurs. It's a reckless statement. 3 of the applications bundled with this software are very well known to have numerous and frequent security holes (exploits) and are often primary targets of your average script kiddie (hacker). I can almost guarantee that any user installing this package without a decent amount of understanding of what they're doing will be hacked, may have their system compromised, and may potentially seek damages from the author.
The potential license violations are another story. I'm not a lawyer, so I won't comment.
A lot of packages at once. - Version: 3.0.1, 9/10/2005 06:55AM PST
(1 of 4 users found this comment useful)
Rufus J
It seems all the snide commentary about this software centers around the inclusion of a version of the Apache server and PHP in OS X. I'd suggest that for someone who desires aome or all of the additional packages, this could easily be considered a reasonable expense. There is a fair amount of configuration savings along with the assurance (hopefully -- I haven't tested this because I don't need it) that everything is properly configured. I feel these comments are unfair and off-base. Those that give one-star ratings based on the redundancy of installing another version of Apache are particularly misguided. It doesn't take too much effort to discover that people do often have problems installing and configuring these apps. mod_jk is especially notorious for failures, for example. DB installation can be an enormous chore...
Perhaps it will serve the community better if those who don't feel the need for some software or another would refrain from dissing that software based on that criterion, and leave the reviewing to those who use or try to use the software and are reporing the results actual usage.
Perhaps it will serve the community better if those who don't feel the need for some software or another would refrain from dissing that software based on that criterion, and leave the reviewing to those who use or try to use the software and are reporing the results actual usage.
Take what you've done and just give it away like those who really did the hard work of designing and writing the programs. They did that on there own time and there own money and just gave it away like this installler should be.
The open software policy is as such. If you take anothers work and make it better (re-writing some code that improves the nature and functionality of the program) you can either give it away or re-package it and sell it for a reasonable price. Other wise you must distribute it for free. Making an installer for free programs does not constitute improvement of the software code and must be distrubted for free. Buddy you best pull this or offer it for free because someone is going to come after you on the legal front and you will be very sorry.
I love the installer but like a previous post said it has security holes and that is like putting a 357 Magnum in the hands of a 3 year old. If you have not done your security work and testing you best pull it now.
Pete