Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 12:12:19 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32133@lists.php.net to get a copy of this message
JR>> This point has nothing to do with file uploads. register_globals is JR>> a disaster regardless of whether or not files are being uploaded. Could you elaborate on this? JR>> The same argument applies to magic_quotes - the lack of any easy way JR>> to tell the difference between a variable which has been magic_quoted JR>> and one which has not will inevitably lead to confusion, and calls JR>> to addslashes() being missed out where they were essential. Errm? _All_ input variables get quoted, AFAIK. Keeping in mind which ones are from outside and which are created by you is your problem, not PHP's. If you are unable to do this, turn magic_quotes off and do addslashes manually. Don't ask PHP to babysit you. JR>> No, PHP is useful, *that* is why it is widely used. That is why JR>> *I* use it. It doesn't make it well-written, or secure, or the JR>> developers clever. You know to do it better? You are welcome to apply for CVS account. -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#32133) next »