Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 14:41:48 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32184@lists.php.net to get a copy of this message | ||
Chuck Hagenbuch <chuck@horde.org> wrote:
> > addslashes (which should also add the single quotes at the beginning and
> > the end like $dbh->quote() in Perl)
>
> Why?
>
> I'm open to the idea that you might have something useful to contribute, but
> you seem to make a lot of assumptions based on your specific coding style.
There are reasons for all of them. Feel free to ask and I will explain.
> That change might save you a few characters of typing, but it would actually
> make addslashes() _less_ flexible. And given the two choices, I would choose
> the current behavior - it is easier to add on a few quotes to the result of
> addslashes() than it would be to strip them off every time you didn't want
> them.
A 'turn this variable into something SQL will treat as a string' is
a better semantic. 'Add slashes to a string' is too ad-hoc. My version
is also more concise. I have tried for a long time using the original
addslashes(), and more recently my new version, and I have found that
in practice the new version is easier to use.
I agree that not adding the slashes is more flexible, but this is only
an advantage if 'add slashes but not quotes' is actually an operation
you would ever want to do. I have never, so far as I can recall, needed
to do this. Have you? What sort of situation are you envisaging where it
would be useful?
Cheers
Jon