RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
| From: | Stanislav Malyshev | Date: | Tue, 05 Sep 2000 12:02:52 +0000 |
| Subject: | RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32129@lists.php.net to get a copy of this message | ||
JM>> HTTP_POST_VARS, HTTP_GET_VARS and turn register_globals off (Thats what
JM>> php.ini is there for, so you can choose how *you* set up PHP.
JM>> HTTP_POST_FILES already exisits AFAIK. Another point about killing
JM>> register_globals is that 99.99% of form processing does not include
JM>> uploading so why should we break this great functionality for this?
I guess we just should say in large friendly letters in the manual "use
HTTP_POST_FILES when you upload files, doing otherwise is insecure!".
At least until we make it safe.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106