Bug->Req #73920 [Opn->Sus]: Reform of file_uploads in php.ini
| From: | cmb@php.net | Date: | Fri, 13 Jan 2017 12:22:45 +0000 |
| Subject: | Bug->Req #73920 [Opn->Sus]: Reform of file_uploads in php.ini | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206594@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73920&edit=1
ID: 73920
Updated by: cmb@php.net
Reported by: admin at yoorshop dot fr
Summary: Reform of file_uploads in php.ini
-Status: Open
+Status: Suspended
-Type: Bug
+Type: Feature/Change Request
Package: URL related
Operating System: centos 6.8
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
The behavior of file_uploads is as expected and not a bug per se,
so this is a feature request. Besides that it's not clear to me
how PHP should check the authorization, introducing a new ini
option would require the RFC process[1], so I'm suspending this
request until someone cares to propose a respective RFC.
[1] <http://wiki.php.net/rfc/howto>
Previous Comments:
------------------------------------------------------------------------
[2017-01-12 12:55:27] admin at yoorshop dot fr
Description:
------------
Hi,
Even if we use CXS to protect websites, it is not sufficient sometimes, many hackers succeeded to
take control over websites by injecting a pyramid of files which are not detected as exploit or
virus, but rather these were efficient php scripts which we truly traveling in the site files until
it got to sensitive datas.
We saw that dozens of times this year, and it is true that some modules/templates with exploits had
facilitated the job of the hacker...
mail, sendmail are now forbidden on our servers, this is also an incredible spam expoit, and
deprecated totally...
file_uploads is a security disease on which PHP community has never made efforts to reform
itselves...
We suggest :
existing file_uploads = OFF all the time
adding a second file_uploads_sess by ex, which can override orignal file_uploads, and which would be
ON by default of course : file_uploads_sess = ON
Conditions are authentication, only those who are authenticated successfully could send a file (only
these need to be able to do that, begining by the webmaster to create his products in his shops or a
blogger post his articles + pictures) :
- webmaster through admin website
- a user forum or client of website also for support by example : he can send a screenshot
- for contact form without authentication : we could introduce a secondary acceptable condition :
captcha
Thanks for attention,
John
Test script:
---------------
Hi,
Even if we use CXS to protect websites, it is not sufficient sometimes, many hackers succeeded to
take control over websites by injecting a pyramid of files which are not detected as exploit or
virus, but rather these were efficient php scripts which we truly traveling in the site files until
it got to sensitive datas.
We saw that dozens of times this year, and it is true that some modules/templates with exploits had
facilitated the job of the hacker...
mail, sendmail are now forbidden on our servers, this is also an incredible spam expoit, and
deprecated totally...
file_uploads is a security disease on which PHP community has never made efforts to reform
itselves...
We suggest :
existing file_uploads = OFF all the time
adding a second file_uploads_sess by ex, which can override orignal file_uploads, and which would be
ON by default of course : file_uploads_sess = ON
Conditions are authentication, only those who are authenticated successfully could send a file (only
these need to be able to do that, begining by the webmaster to create his products in his shops or a
blogger post his articles + pictures) :
- webmaster through admin website
- a user forum or client of website also for support by example : he can send a screenshot
- for contact form without authentication : we could introduce a secondary acceptable condition :
captcha
Thanks for attention,
John
Expected result:
----------------
Hi,
Even if we use CXS to protect websites, it is not sufficient sometimes, many hackers succeeded to
take control over websites by injecting a pyramid of files which are not detected as exploit or
virus, but rather these were efficient php scripts which we truly traveling in the site files until
it got to sensitive datas.
We saw that dozens of times this year, and it is true that some modules/templates with exploits had
facilitated the job of the hacker...
mail, sendmail are now forbidden on our servers, this is also an incredible spam expoit, and
deprecated totally...
file_uploads is a security disease on which PHP community has never made efforts to reform
itselves...
We suggest :
existing file_uploads = OFF all the time
adding a second file_uploads_sess by ex, which can override orignal file_uploads, and which would be
ON by default of course : file_uploads_sess = ON
Conditions are authentication, only those who are authenticated successfully could send a file (only
these need to be able to do that, begining by the webmaster to create his products in his shops or a
blogger post his articles + pictures) :
- webmaster through admin website
- a user forum or client of website also for support by example : he can send a screenshot
- for contact form without authentication : we could introduce a secondary acceptable condition :
captcha
Thanks for attention,
John
Actual result:
--------------
Hi,
Even if we use CXS to protect websites, it is not sufficient sometimes, many hackers succeeded to
take control over websites by injecting a pyramid of files which are not detected as exploit or
virus, but rather these were efficient php scripts which we truly traveling in the site files until
it got to sensitive datas.
We saw that dozens of times this year, and it is true that some modules/templates with exploits had
facilitated the job of the hacker...
mail, sendmail are now forbidden on our servers, this is also an incredible spam expoit, and
deprecated totally...
file_uploads is a security disease on which PHP community has never made efforts to reform
itselves...
We suggest :
existing file_uploads = OFF all the time
adding a second file_uploads_sess by ex, which can override orignal file_uploads, and which would be
ON by default of course : file_uploads_sess = ON
Conditions are authentication, only those who are authenticated successfully could send a file (only
these need to be able to do that, begining by the webmaster to create his products in his shops or a
blogger post his articles + pictures) :
- webmaster through admin website
- a user forum or client of website also for support by example : he can send a screenshot
- for contact form without authentication : we could introduce a secondary acceptable condition :
captcha
Thanks for attention,
John
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73920&edit=1