Hacker News new | ask | show | jobs
by blueimp 2798 days ago
Thanks for your comment.

I do think that I share at least part of the blame. Enabling all file types by default was not necessary and would have prevented this issue.

Especially since there are so many inexperienced developers using PHP, the defaults should have been secure in every perceivable Webserver configuration.