Re: PHP File Upload Security Hole - Still No Fix?
| From: | Peter Korsgaard | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32144@lists.php.net to get a copy of this message | ||
On Tue, 5 Sep 2000, Jon Ribbens wrote:
> I bet there are thousands of scripts out there that rely on variables
> being unset at the start of their execution, that could be persuaded
> to do bad things by setting the variables via CGI variables. I bet there
> are thousands more which have bugs due to confusion as to where a variable
> came from.
Couldn't we instead implement warnings as in gcc which tell you if you use
an unitialised variable? That way evil hackers couldn't overwrite our
trusted variables.
--
Bye, Peter Korsgaard