Re: PHP File Upload Security Hole - Still No Fix?
| From: | Rasmus Lerdorf | Date: | Tue, 05 Sep 2000 14:23:16 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32172@lists.php.net to get a copy of this message | ||
> Rasmus Lerdorf <rasmus@php.net> wrote:
> > > Sorry to be blunt, but you can verify this yourself by looking in
> > > the list archives.
> >
> > I understood it fine.
>
> Other people can check that for themselves in the archives.
>
> I await with interest your explanation of why you kept making totally
> incorrect claims about shell metacharacters.
It was a usage difference. You said the function was completely
useless. I said it was quite useful the way I have always used it. ie.
$a = "a;b";
$b = "c;d";
$a = escapeshellcmd($a);
$b = escapeshellcmd($b);
system("ls $a $b");
But regardless, I'm not the one blocking anything. There are dozens of
people who read php-dev with cvs commit access and you didn't manage to
convince any of them to commit your code.
You may very well be right that we need another shell escape function,
which I actually never disagreed with, but you don't seem to be doing a
very good job convincing anybody to use your code. I guess we are all too
stupid to understand your brilliance.
-Rasmus