Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 13:44:15 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32153@lists.php.net to get a copy of this message | ||
Johan Andersson <johan@andersson.net> wrote:
> As many others I know, I teach my friends PHP.. And I teach them to use
> $HTTP* and always describes the security pitfalls by not using them.
> And if you, Jon, say you helping people with their code, why just don't you
> tell them as we other do
Because people don't ask me. Who am I? They go and read the PHP manual, like
they should. The documentation needs to be in the PHP manual, not some
random web page I could write which nobody would read.
> It is easy to write a unsecure website with php if you don't know about all
> this (and keeps on using "register_globals" etc), but that's the same with
> so many other languages, and of course you have to learn how to write a well
> written code as in EVERY programming language on earth!
Yes, but most languages don't have features which add nothing except
security holes, which are enabled by default, and which are not cautioned
against in the documentation!
> I just say that all the php developers that I've spoked to on the net and in
> real life that uses the "register_globals" functionality is because they are
> too lazy to type $HTTP_*_VARS[].
> But hey, what could we say, lazy developers do lazy code. Lazy code,
> unsecure code..
PHP has no need to cause people RSI, though. The standard PHP library I use
has 1-letter functions for all this stuff, 'F' to get form variables, 'H'
for 'htmlentities', 'S' for 'addslashes', etc. If PHP had this stuff
built-in
then even lazy people would be doing things the secure way.
Cheers
Jon