Re: PHP File Upload Security Hole - Still No Fix?
| From: | Stanislav Malyshev | Date: | Tue, 05 Sep 2000 11:46:46 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32126@lists.php.net to get a copy of this message | ||
JR>> It was caused by the register_globals *ethos* that it is fine to
JR>> mix trusted and untrusted data with no way of telling which is
JR>> which.
All data is untrusted. We just make it a bit easier to check them.
JR>> There is? It is not documented in
JR>> /manual/language.variables.predefined.php or
JR>> /manual/features.file-upload.php. Where can I find information
JR>> on this?
Well, this is pretty new addition - maybe it didn't get in the docs yet.
If you need it too bad just cry on phpdoc@lists.php.net and somebody will
do it. PHP is not 100% documented yet, this is known fact and it will
never be 100% documented in given amount of time, given the ongoing
development and general nature of the project.
JR>> I didn't say close the other way. I said make a way so that people can
JR>> change their scripts to be secure. At the moment, there is no way to
JR>> write code to safely receive a generic file.
See above for HTTP_POST_FILES. Why is it unsafe?
As for "I didn't say close" - you did say "remove register_globals from
PHP".
JR>> > JR>> 'register_globals', and magic_quotes features, and try and
JR>> > JR>> remove
JR>> > JR>> them completely in a later version of PHP. They are both recipes
JR>> Yes. That's why I said 'deprecate' it not 'remove' it. Make
Well, or I'm hallucinating or you did say "remove". I guess this won't
happen. Using them indeed might be no good (though if you don't do file
uploads, you have nothing to fear from globals).
JR>> No, I'm saying "because security is only about 10%, don't give
JR>> people a false sense of security by pretending it works".
How exactly did you calculate those 10%? Can you please provide as with
audit of safe_mode and it's deficiencies?
As for "pretending" - "safe mode" was unfortunate name indeed. It's not
"safe", it's just "restrictive". I guess it's too late to rename it,
though. Also, it does need rework, and the rework is in TODO list - just
nobody came to do it yet. Would you?
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106