Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 12:53:01 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32140@lists.php.net to get a copy of this message | ||
Zeev Suraski <zeev@zend.com> wrote:
> I fully agree that using register_globals is a bad idea, and a bad
> concept. This is one of the reasons i made track_vars on by default for
> PHP 4.0, and personally encourage people to use these arrays, and have
> register_globals turned off.
Can I suggest that adding in a concise syntax to access the variables
would be an excellent idea? People are never going to sit there typing
'$HTTP_POST_VARS' all the way through their script. Yes, you can add in
a function in a library, but a lot of people aren't going to do that
(and PHP's philosophy appears to be to put everything built-in anyway ;-) ).
If you had a '%var' syntax, or a built-in function with a very short name,
I think this would help immensely.