Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 14:16:42 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32170@lists.php.net to get a copy of this message | ||
Johan Andersson <johan@andersson.net> wrote:
> My opionion of you is that you are just a very lazy developer
You're a fool if you think you can reach that conclusion from what I've
posted on this thread. But don't feel bad, you're not the only one.
> that had something personal incident with Rasmus and then you came to
> php-dev to critise him and Zeev for their hard work...
Oh, sorry, I must bow before the mighty Zeev and Rasmus and thank them
humbly for the security disasters they have granted to the human race.
> So why just don't you take your hours to contribute some documentation
> instead of this bad, totally unnecessary criticism.
You didn't notice all the constructive suggestions then? I suggest you
go look harder.
I cannot write the documentation. I'm not in charge of PHP strategy or
design. Do you not understand what documentation is and does? Documentation
is a guarantee of what works, and what will work in the future. How should
I know the answers to these questions?
> I'm sitting here thinking that if all functions in the php extensions for
> example should have one-letter function names.
That's nice for you. Why would you be sitting there thinking that?
I would only suggest that 3 or 4 of the most frequently used functions
would be given short names. I would recommend, maybe: htmlentities, urlencode,
addslashes (which should also add the single quotes at the beginning and
the end like $dbh->quote() in Perl), and something to fetch CGI variables.
Sheesh, the one-letter thing is a compromise on my part anyway to make things
easier for programmers. Making things easier for programmers is usually not
the right thing to do.
> How would that source look like?
I don't know, it's your imagination - not mine.
Cheers
Jon