Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 13:26:26 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-32147@lists.php.net to get a copy of this message
Since I started to use PHP (version 3.x something) and many others I know using it always type $HTTP_POST_VARS and are not so lazy just typing like "if($varname)" to access $HTTP_GET_VARS['varname']. (or HTTP_POST_FILES as was in subject) But there is those people that I ask why they don't use $HTTP* is often cause it's so EASY to just use the "register_globals" functionality. As many others I know, I teach my friends PHP.. And I teach them to use $HTTP* and always describes the security pitfalls by not using them. And if you, Jon, say you helping people with their code, why just don't you tell them as we other do (like I say I do, like Zeev and all the other recommends) that not to use the "register_globals" functionality. I just think you are a bit correct in what you say though. It is easy to write a unsecure website with php if you don't know about all this (and keeps on using "register_globals" etc), but that's the same with so many other languages, and of course you have to learn how to write a well written code as in EVERY programming language on earth! So, point your critisism on the people your are trying to help rather than the dev team. I just say that all the php developers that I've spoked to on the net and in real life that uses the "register_globals" functionality is because they are too lazy to type $HTTP_*_VARS[]. But hey, what could we say, lazy developers do lazy code. Lazy code, unsecure code.. Just wanted to post my opinion in this since I and some collegues has discussed this thread all day long.. :) Regards, Johan Andersson Consultant, Qbranch AB ----- Original Message ----- From: Jon Ribbens <jon+php-dev@unequivocal.co.uk> To: Zeev Suraski <zeev@zend.com> Cc: <php-dev@lists.php.net> Sent: Tuesday, September 05, 2000 2:53 PM Subject: Re: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? > Zeev Suraski <zeev@zend.com> wrote: > > I fully agree that using register_globals is a bad idea, and a bad > > concept. This is one of the reasons i made track_vars on by default for > > PHP 4.0, and personally encourage people to use these arrays, and have > > register_globals turned off. > > Can I suggest that adding in a concise syntax to access the variables > would be an excellent idea? People are never going to sit there typing > '$HTTP_POST_VARS' all the way through their script. Yes, you can add in > a function in a library, but a lot of people aren't going to do that > (and PHP's philosophy appears to be to put everything built-in anyway ;-) ). > > If you had a '%var' syntax, or a built-in function with a very short name, > I think this would help immensely. > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.dev (#32147) next »