Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 12:48:59 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32138@lists.php.net to get a copy of this message
Stanislav Malyshev <stas@zend.com> wrote: > JR>> It was caused by the register_globals *ethos* that it is fine to > JR>> mix trusted and untrusted data with no way of telling which is > JR>> which. > > All data is untrusted. We just make it a bit easier to check them. No, data from the user is untrusted. Data that PHP itself provides (i.e. the filename of the local file) is (and has to be) trusted. Data from other parts of the script is trusted. > Well, this is pretty new addition - maybe it didn't get in the docs yet. > If you need it too bad just cry on phpdoc@lists.php.net and somebody will > do it. PHP is not 100% documented yet, this is known fact and it will > never be 100% documented in given amount of time, given the ongoing > development and general nature of the project. That's fair enough, but this particular documentation omission is a major security hole. If you care about security at all, it must be fixed. > JR>> I didn't say close the other way. I said make a way so that people can > JR>> change their scripts to be secure. At the moment, there is no way to > JR>> write code to safely receive a generic file. > > See above for HTTP_POST_FILES. Why is it unsafe? It is unsafe if HTTP_POST_FILES doesn't exist. And, to all intents and purposes, it doesn't. > As for "I didn't say close" - you did say "remove register_globals from > PHP". Yes, "in a later version" as a final goal. Not anytime soon. > Using them indeed might be no good (though if you don't do file > uploads, you have nothing to fear from globals). You always have something to fear. It means that trusted data from your own PHP scripts is indistinguishable from untrusted data from user input. This is a Very Bad Thing. The file upload problem is simply one sympton of a much more general sickness. > How exactly did you calculate those 10%? Can you please provide as with > audit of safe_mode and it's deficiencies? Well, gee, no, I don't feel like auditing your code. You wouldn't like what I said if I did, anyway. And as you freely admit, the problem is one of documentation and not of code anyway - safe mode is not *meant* to be 'safe'. > Also, it does need rework, and the rework is in TODO list - just nobody > came to do it yet. Would you? Well, the last time I wrote some code for PHP, it was completely ignored with no explanation given. So I'm not particularly disposed to contribute. Cheers Jon

« previous php.dev (#32138) next »