Hacker News new | ask | show | jobs
by ryanlol 3810 days ago
Yeah, Hetzner also has this strange habit of spitting out SQL errors when you put apostrophes into forms on their website.

I'd avoid them.

2 comments

At least a few years ago, shared hosting with Hetzner used to be a complete security mess. By default, every user could access many other users' www directories via SFTP, including loads of PHP config files with MySQL access data inside. No SFTP jails in place, no automated process to prevent 775 (or 777!) permissions. (Yes, you could delete other users' whole www directories.) Real names of all users on the same server world-readable in /etc/passwd. Didn't exactly increase my trust in their products.
As someone who just applied for (and failed to get) a job at a DB company:

Not sanitizing your inputs is unacceptable, even for a newbie. These guys must be really stupid.

They are to big to fail at this point. And based on their price the servers are amazing. (If you dont care about a perfect uptime.)