Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 13:01:45 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32142@lists.php.net to get a copy of this message | ||
Stanislav Malyshev <stas@zend.com> wrote:
> JR>> This point has nothing to do with file uploads. register_globals is
> JR>> a disaster regardless of whether or not files are being uploaded.
>
> Could you elaborate on this?
Simply the obvious problem that it mixes trusted and untrusted data
together, and you can't tell which is which.
I bet there are thousands of scripts out there that rely on variables
being unset at the start of their execution, that could be persuaded
to do bad things by setting the variables via CGI variables. I bet there
are thousands more which have bugs due to confusion as to where a variable
came from.
> Errm? _All_ input variables get quoted, AFAIK. Keeping in mind which ones
> are from outside and which are created by you is your problem, not
> PHP's.
Yes, it is the script author's problem. But it is a problem which has
been created artifically by PHP. If PHP didn't have this mis-feature,
the problem simply wouldn't exist. It's very similar to the globals
problem - escaped and non-escaped data is mixed together with no way
of telling which is which.
You can't make things *too* simple for the programmer. Some things
simply require attention-to-detail. Making things mostly work when
the programmer doesn't pay attention is not doing them a favour.
Security problems aren't usually obvious to the sort of testing
most people do.
> If you are unable to do this, turn magic_quotes off and do
> addslashes manually. Don't ask PHP to babysit you.
I'm not asking it to babysit me. I'm asking it not to put landmines in
my path. (Yes, I know I can turn it off in my installation. That doesn't
help everyone who is going to start learning PHP tomorrow and to whom
it isn't instantly obvious how harmful magic_quotes are.)
> You know to do it better? You are welcome to apply for CVS account.
Sorry, the PHP source makes me feel ill.
Cheers
Jon