Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 14:05:14 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5  Groups: php.dev 
Request: Send a blank email to php-dev+get-32164@lists.php.net to get a copy of this message
My opionion of you is that you are just a very lazy developer that had something personal incident with Rasmus and then you came to php-dev to critise him and Zeev for their hard work... And yeah.. as EVERYONE says; Things like HTTP_POST_FILES should be documented, but as Zeev also said.. The documentation will never be up to date with the development. So why just don't you take your hours to contribute some documentation instead of this bad, totally unnecessary criticism. That does NOT contribute in any way to the PHP development. Specially with that tone of yours in your first letter. I'm sitting here thinking that if all functions in the php extensions for example should have one-letter function names. How would that source look like? I just say that there IS a meaning of why the PHP language (and other languages too) is structured in that way they are. Cheers to you too, Jon. ----- Original Message ----- From: Jon Ribbens <jon+php-dev@unequivocal.co.uk> To: <php-dev@lists.php.net> Sent: Tuesday, September 05, 2000 3:44 PM Subject: Re: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? > Johan Andersson <johan@andersson.net> wrote: > > As many others I know, I teach my friends PHP.. And I teach them to use > > $HTTP* and always describes the security pitfalls by not using them. > > And if you, Jon, say you helping people with their code, why just don't you > > tell them as we other do > > Because people don't ask me. Who am I? They go and read the PHP manual, like > they should. The documentation needs to be in the PHP manual, not some > random web page I could write which nobody would read. > > > It is easy to write a unsecure website with php if you don't know about all > > this (and keeps on using "register_globals" etc), but that's the same with > > so many other languages, and of course you have to learn how to write a well > > written code as in EVERY programming language on earth! > > Yes, but most languages don't have features which add nothing except > security holes, which are enabled by default, and which are not cautioned > against in the documentation! > > > I just say that all the php developers that I've spoked to on the net and in > > real life that uses the "register_globals" functionality is because they are > > too lazy to type $HTTP_*_VARS[]. > > But hey, what could we say, lazy developers do lazy code. Lazy code, > > unsecure code.. > > PHP has no need to cause people RSI, though. The standard PHP library I use > has 1-letter functions for all this stuff, 'F' to get form variables, 'H' > for 'htmlentities', 'S' for 'addslashes', etc. If PHP had this > stuff built-in > then even lazy people would be doing things the secure way. > > Cheers > > > Jon > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.dev (#32164) next »