Re: PHP File Upload Security Hole - Still No Fix?
| From: | Stanislav Malyshev | Date: | Tue, 05 Sep 2000 12:12:19 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32133@lists.php.net to get a copy of this message | ||
JR>> This point has nothing to do with file uploads. register_globals is
JR>> a disaster regardless of whether or not files are being uploaded.
Could you elaborate on this?
JR>> The same argument applies to magic_quotes - the lack of any easy way
JR>> to tell the difference between a variable which has been magic_quoted
JR>> and one which has not will inevitably lead to confusion, and calls
JR>> to addslashes() being missed out where they were essential.
Errm? _All_ input variables get quoted, AFAIK. Keeping in mind which ones
are from outside and which are created by you is your problem, not
PHP's. If you are unable to do this, turn magic_quotes off and do
addslashes manually. Don't ask PHP to babysit you.
JR>> No, PHP is useful, *that* is why it is widely used. That is why
JR>> *I* use it. It doesn't make it well-written, or secure, or the
JR>> developers clever.
You know to do it better? You are welcome to apply for CVS account.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106