Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 15:08:39 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32191@lists.php.net to get a copy of this message
James Moore <jmoore@php.net> wrote: > If you feel this why not checkout a copy of the PHP CVS and go off and > develop it yourself, alter it how you want, there is no licience stopping > you doing this, if you are unhappy with a feature of PHP change it, either > send a patch back to the php dev list explaining what it does and how it > does it and if it is seen as useful then I am sure it will be commited to > CVS. None of the things I have suggested involve any particular coding effort. They are design decisions which the PHP team have to take. Once the decisions are taken, the coding required is minimal. Adding a function to read the form variables, for example, is very easy. As is setting register_globals to 'off' by default in the PHP distribution. Coding is not what is required. > Now if you have some real criticism then fine tell the development team, I > hope they all (like they should) be receptive to constructive criticism, the > criticism you are currently leveling is totally ludicrous, What, all the individual points I have made are all ludicrous? Fancy that. > Saying things like <quot>The PHP interpreter is nowhere near well-written > enough for this feature to be of any use at all.</quot> That's taken out of context. The PHP code is fine for doing what it usually does. If you try to use it for something unusual, i.e. safe_mode, then it is not good at this. The PHP developers said as much on this list today! > You have shown a blatient disrespect for them and no wonder your > suggestions are getting nowhere. If the developers are so masterful and wise, I am sure they are perfectly capable of extracting reason from insult in my emails. I said as much in the first email. Right at the top. The first PHP developer to reply did very well.

« previous php.dev (#32191) next »