RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 14:27:37 +0000
Subject: RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32174@lists.php.net to get a copy of this message
> Look, really, I think the only way to access CGI variables should be > through a function such as GET_EVIL_UNTRUSTED_CGI_VARIABLE() or somesuch. > This would probably be impractical, so I would settle for simply having > to call a function or use some other special syntax. Mixing them in with > the global variables is just ludicrous. If you feel this why not checkout a copy of the PHP CVS and go off and develop it yourself, alter it how you want, there is no licience stopping you doing this, if you are unhappy with a feature of PHP change it, either send a patch back to the php dev list explaining what it does and how it does it and if it is seen as useful then I am sure it will be commited to CVS. PHP is Open Source, people do it off their own back and the majority of the time dont get paid. Now I agree that %a (or somthing similar) might be an nice way of accessing form variables (I am not that familliar with the source of PHP and how everything is implemented) so it might not be reasonable for other reasons that this is done. Perhaps Zeev, Rasmus etc could enlighten us. I am one of these very lazy programmers who relies on register_globals for form processing apart from when it comes to file uploads. Now if you have some real criticism then fine tell the development team, I hope they all (like they should) be receptive to constructive criticism, the criticism you are currently leveling is totally ludicrous, you are slagging of the majority of their last 3-5years work in sweeping statements, of course they will get defensive, it is human nature. I do not think you have earned the right to critise PHP like this, If you have specific holes then yes but not genrally. Saying things like <quot>The PHP interpreter is nowhere near well-written enough for this feature to be of any use at all.</quot> Is just inviting flames, I think firstly you need to think about the language you use and then level the criticisms at PHP while respecting the PHP Development team who all work very hard. You have shown a blatient disrespect for them and no wonder your suggestions are getting nowhere. <profound>You Reap what you Sow</profound> Thanks James

« previous php.dev (#32174) next »