Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 13:01:45 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32142@lists.php.net to get a copy of this message
Stanislav Malyshev <stas@zend.com> wrote: > JR>> This point has nothing to do with file uploads. register_globals is > JR>> a disaster regardless of whether or not files are being uploaded. > > Could you elaborate on this? Simply the obvious problem that it mixes trusted and untrusted data together, and you can't tell which is which. I bet there are thousands of scripts out there that rely on variables being unset at the start of their execution, that could be persuaded to do bad things by setting the variables via CGI variables. I bet there are thousands more which have bugs due to confusion as to where a variable came from. > Errm? _All_ input variables get quoted, AFAIK. Keeping in mind which ones > are from outside and which are created by you is your problem, not > PHP's. Yes, it is the script author's problem. But it is a problem which has been created artifically by PHP. If PHP didn't have this mis-feature, the problem simply wouldn't exist. It's very similar to the globals problem - escaped and non-escaped data is mixed together with no way of telling which is which. You can't make things *too* simple for the programmer. Some things simply require attention-to-detail. Making things mostly work when the programmer doesn't pay attention is not doing them a favour. Security problems aren't usually obvious to the sort of testing most people do. > If you are unable to do this, turn magic_quotes off and do > addslashes manually. Don't ask PHP to babysit you. I'm not asking it to babysit me. I'm asking it not to put landmines in my path. (Yes, I know I can turn it off in my installation. That doesn't help everyone who is going to start learning PHP tomorrow and to whom it isn't instantly obvious how harmful magic_quotes are.) > You know to do it better? You are welcome to apply for CVS account. Sorry, the PHP source makes me feel ill. Cheers Jon

« previous php.dev (#32142) next »