Earlier quoted context omitted.
Dynamicity usually refers to the fact that you can execute code that wasn't fully specified at runtime. Lisp code is the stereotypical example of a dynamic programming language because it can update its own code while being executed. On the other hand, compiled C code is static because the code is loaded into memory and cannot be changed during the execution (as a matter of fact, the memory pages holding the code don…
> Dynamicity usually refers to the fact that you can execute code that wasn't fully specified at runtime. As in eval()'ing code based on user input? That's pretty crazy, and I don't think (hope) a lot of real world security problems are caused by that! > Back to our problem: A dynamic website will typically take user input (e.g. the user name) and build a personalized view of the webpage for the user But this has lit…
His claim is that the mere fact that the language contains an "eval()" function (which is a feature of dynamic languages) inevitably increases the risk.
Quoting: Most of the computer languages used to write web applications such as DCMS systems contain a feature called eval, where programming instructions can be deliberately promoted from data to code at runtime. [...] but when it is left accessible to unskilled or malicious users, eval is a recipe for disaster.
> A TLDR of the original article: "Handling user input can be dangerous, it's safer if you don't." But we already knew that...
I would say:
1. DCMS are bad for public facing webserver because they process user inputs with a language that supports function as powerful as "eval".
2. DCMS are bad for public facing webserver because they run slow interpreted which is "1000 times" slower and enable DDOS