Re: PHP File Upload Security Hole - Still No Fix?
| From: | Johan Andersson | Date: | Tue, 05 Sep 2000 13:35:51 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32149@lists.php.net to get a copy of this message | ||
Exactly what I was saying too..
Like in languages noticed earlier today, ColdFusion, where you have the prefix
URL.varname and Form.varname.
Very easy to do the same look-a-like in php as Mårten said.
And as I meantioned in my last e-mail that was the same as Rasmus said:
"We need to educate users a bit better on security issues, but with or
without register_globals you can never trust user input. register_globals
is not the real problem and removing it will not magically solve anything"
So, Jon, and all others that might complain about the "security hole" as you
calls it, educate the people you are helping, and don't be so lazy when writing
your code. :)
And at last, Zeev, Stas and all the other people that are working hard with the
development of PHP does not deserve that critisism of your neither that tone.
And I think it sounds VERY strange that your contribution to the PHP development was totally
ignored.
I'm very interested if you could tell me some more about that..
----- Original Message -----
From: Gustafson, Mårten <marten@jerbro.se>
To: <php-dev@lists.php.net>
Sent: Tuesday, September 05, 2000 3:27 PM
Subject: RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
I don´t think anything has to be changed.
It´s not a hard thing to do $form = &$HTTP_POST_VARS at the top of each
script that should recive post data. Or have a general include file that
takes care of it.
Regards
Mårten
> -----Original Message-----
> From: Jon Ribbens [mailto:jon+php-dev@unequivocal.co.uk]
> Sent: Tuesday, September 05, 2000 2:53 PM
> To: Zeev Suraski
> Cc: php-dev@lists.php.net
> Subject: Re: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
>
> Can I suggest that adding in a concise syntax to access the variables
> would be an excellent idea? People are never going to sit there typing
> '$HTTP_POST_VARS' all the way through their script. Yes, you
> can add in
> a function in a library, but a lot of people aren't going to do that
> (and PHP's philosophy appears to be to put everything
> built-in anyway ;-) ).
>
> If you had a '%var' syntax, or a built-in function with a
> very short name,
> I think this would help immensely.
--
PHP Development Mailing List <http://www.php.net/>
To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
For additional commands, e-mail: php-dev-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net