Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 11:46:46 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32126@lists.php.net to get a copy of this message
JR>> It was caused by the register_globals *ethos* that it is fine to JR>> mix trusted and untrusted data with no way of telling which is JR>> which. All data is untrusted. We just make it a bit easier to check them. JR>> There is? It is not documented in JR>> /manual/language.variables.predefined.php or JR>> /manual/features.file-upload.php. Where can I find information JR>> on this? Well, this is pretty new addition - maybe it didn't get in the docs yet. If you need it too bad just cry on phpdoc@lists.php.net and somebody will do it. PHP is not 100% documented yet, this is known fact and it will never be 100% documented in given amount of time, given the ongoing development and general nature of the project. JR>> I didn't say close the other way. I said make a way so that people can JR>> change their scripts to be secure. At the moment, there is no way to JR>> write code to safely receive a generic file. See above for HTTP_POST_FILES. Why is it unsafe? As for "I didn't say close" - you did say "remove register_globals from PHP". JR>> > JR>> 'register_globals', and magic_quotes features, and try and JR>> > JR>> remove JR>> > JR>> them completely in a later version of PHP. They are both recipes JR>> Yes. That's why I said 'deprecate' it not 'remove' it. Make Well, or I'm hallucinating or you did say "remove". I guess this won't happen. Using them indeed might be no good (though if you don't do file uploads, you have nothing to fear from globals). JR>> No, I'm saying "because security is only about 10%, don't give JR>> people a false sense of security by pretending it works". How exactly did you calculate those 10%? Can you please provide as with audit of safe_mode and it's deficiencies? As for "pretending" - "safe mode" was unfortunate name indeed. It's not "safe", it's just "restrictive". I guess it's too late to rename it, though. Also, it does need rework, and the rework is in TODO list - just nobody came to do it yet. Would you? -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#32126) next »