Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 14:16:42 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6  Groups: php.dev 
Request: Send a blank email to php-dev+get-32170@lists.php.net to get a copy of this message
Johan Andersson <johan@andersson.net> wrote: > My opionion of you is that you are just a very lazy developer You're a fool if you think you can reach that conclusion from what I've posted on this thread. But don't feel bad, you're not the only one. > that had something personal incident with Rasmus and then you came to > php-dev to critise him and Zeev for their hard work... Oh, sorry, I must bow before the mighty Zeev and Rasmus and thank them humbly for the security disasters they have granted to the human race. > So why just don't you take your hours to contribute some documentation > instead of this bad, totally unnecessary criticism. You didn't notice all the constructive suggestions then? I suggest you go look harder. I cannot write the documentation. I'm not in charge of PHP strategy or design. Do you not understand what documentation is and does? Documentation is a guarantee of what works, and what will work in the future. How should I know the answers to these questions? > I'm sitting here thinking that if all functions in the php extensions for > example should have one-letter function names. That's nice for you. Why would you be sitting there thinking that? I would only suggest that 3 or 4 of the most frequently used functions would be given short names. I would recommend, maybe: htmlentities, urlencode, addslashes (which should also add the single quotes at the beginning and the end like $dbh->quote() in Perl), and something to fetch CGI variables. Sheesh, the one-letter thing is a compromise on my part anyway to make things easier for programmers. Making things easier for programmers is usually not the right thing to do. > How would that source look like? I don't know, it's your imagination - not mine. Cheers Jon

« previous php.dev (#32170) next »