Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 13:35:51 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32149@lists.php.net to get a copy of this message
Exactly what I was saying too.. Like in languages noticed earlier today, ColdFusion, where you have the prefix URL.varname and Form.varname. Very easy to do the same look-a-like in php as Mårten said. And as I meantioned in my last e-mail that was the same as Rasmus said: "We need to educate users a bit better on security issues, but with or without register_globals you can never trust user input. register_globals is not the real problem and removing it will not magically solve anything" So, Jon, and all others that might complain about the "security hole" as you calls it, educate the people you are helping, and don't be so lazy when writing your code. :) And at last, Zeev, Stas and all the other people that are working hard with the development of PHP does not deserve that critisism of your neither that tone. And I think it sounds VERY strange that your contribution to the PHP development was totally ignored. I'm very interested if you could tell me some more about that.. ----- Original Message ----- From: Gustafson, Mårten <marten@jerbro.se> To: <php-dev@lists.php.net> Sent: Tuesday, September 05, 2000 3:27 PM Subject: RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? I don´t think anything has to be changed. It´s not a hard thing to do $form = &$HTTP_POST_VARS at the top of each script that should recive post data. Or have a general include file that takes care of it. Regards Mårten > -----Original Message----- > From: Jon Ribbens [mailto:jon+php-dev@unequivocal.co.uk] > Sent: Tuesday, September 05, 2000 2:53 PM > To: Zeev Suraski > Cc: php-dev@lists.php.net > Subject: Re: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? > > Can I suggest that adding in a concise syntax to access the variables > would be an excellent idea? People are never going to sit there typing > '$HTTP_POST_VARS' all the way through their script. Yes, you > can add in > a function in a library, but a lot of people aren't going to do that > (and PHP's philosophy appears to be to put everything > built-in anyway ;-) ). > > If you had a '%var' syntax, or a built-in function with a > very short name, > I think this would help immensely. -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#32149) next »