Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 12:48:59 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32138@lists.php.net to get a copy of this message | ||
Stanislav Malyshev <stas@zend.com> wrote:
> JR>> It was caused by the register_globals *ethos* that it is fine to
> JR>> mix trusted and untrusted data with no way of telling which is
> JR>> which.
>
> All data is untrusted. We just make it a bit easier to check them.
No, data from the user is untrusted. Data that PHP itself provides
(i.e. the filename of the local file) is (and has to be) trusted. Data
from other parts of the script is trusted.
> Well, this is pretty new addition - maybe it didn't get in the docs yet.
> If you need it too bad just cry on phpdoc@lists.php.net and somebody will
> do it. PHP is not 100% documented yet, this is known fact and it will
> never be 100% documented in given amount of time, given the ongoing
> development and general nature of the project.
That's fair enough, but this particular documentation omission is a major
security hole. If you care about security at all, it must be fixed.
> JR>> I didn't say close the other way. I said make a way so that people can
> JR>> change their scripts to be secure. At the moment, there is no way to
> JR>> write code to safely receive a generic file.
>
> See above for HTTP_POST_FILES. Why is it unsafe?
It is unsafe if HTTP_POST_FILES doesn't exist. And, to all intents and
purposes, it doesn't.
> As for "I didn't say close" - you did say "remove register_globals from
> PHP".
Yes, "in a later version" as a final goal. Not anytime soon.
> Using them indeed might be no good (though if you don't do file
> uploads, you have nothing to fear from globals).
You always have something to fear. It means that trusted data from your
own PHP scripts is indistinguishable from untrusted data from user input.
This is a Very Bad Thing. The file upload problem is simply one sympton
of a much more general sickness.
> How exactly did you calculate those 10%? Can you please provide as with
> audit of safe_mode and it's deficiencies?
Well, gee, no, I don't feel like auditing your code. You wouldn't like
what I said if I did, anyway. And as you freely admit, the problem is one of
documentation and not of code anyway - safe mode is not *meant* to be 'safe'.
> Also, it does need rework, and the rework is in TODO list - just nobody
> came to do it yet. Would you?
Well, the last time I wrote some code for PHP, it was completely ignored
with no explanation given. So I'm not particularly disposed to contribute.
Cheers
Jon