RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
| From: | James Moore | Date: | Tue, 05 Sep 2000 14:27:37 +0000 |
| Subject: | RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32174@lists.php.net to get a copy of this message | ||
> Look, really, I think the only way to access CGI variables should be
> through a function such as GET_EVIL_UNTRUSTED_CGI_VARIABLE() or somesuch.
> This would probably be impractical, so I would settle for simply having
> to call a function or use some other special syntax. Mixing them in with
> the global variables is just ludicrous.
If you feel this why not checkout a copy of the PHP CVS and go off and
develop it yourself, alter it how you want, there is no licience stopping
you doing this, if you are unhappy with a feature of PHP change it, either
send a patch back to the php dev list explaining what it does and how it
does it and if it is seen as useful then I am sure it will be commited to
CVS.
PHP is Open Source, people do it off their own back and the majority of the
time dont get paid. Now I agree that %a (or somthing similar) might be an
nice way of accessing form variables (I am not that familliar with the
source of PHP and how everything is implemented) so it might not be
reasonable for other reasons that this is done. Perhaps Zeev, Rasmus etc
could enlighten us. I am one of these very lazy programmers who relies on
register_globals for form processing apart from when it comes to file
uploads.
Now if you have some real criticism then fine tell the development team, I
hope they all (like they should) be receptive to constructive criticism, the
criticism you are currently leveling is totally ludicrous, you are slagging
of the majority of their last 3-5years work in sweeping statements, of
course they will get defensive, it is human nature. I do not think you have
earned the right to critise PHP like this, If you have specific holes then
yes but not genrally. Saying things like <quot>The PHP interpreter is
nowhere near well-written enough for this feature to be of any use at
all.</quot> Is just inviting flames, I think firstly you need to think about
the language you use and then level the criticisms at PHP while respecting
the PHP Development team who all work very hard. You have shown a blatient
disrespect for them and no wonder your suggestions are getting nowhere.
<profound>You Reap what you Sow</profound>
Thanks
James