Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 15:08:39 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32191@lists.php.net to get a copy of this message | ||
James Moore <jmoore@php.net> wrote:
> If you feel this why not checkout a copy of the PHP CVS and go off and
> develop it yourself, alter it how you want, there is no licience stopping
> you doing this, if you are unhappy with a feature of PHP change it, either
> send a patch back to the php dev list explaining what it does and how it
> does it and if it is seen as useful then I am sure it will be commited to
> CVS.
None of the things I have suggested involve any particular coding effort.
They are design decisions which the PHP team have to take. Once the
decisions are taken, the coding required is minimal. Adding a function
to read the form variables, for example, is very easy. As is setting
register_globals to 'off' by default in the PHP distribution.
Coding is not what is required.
> Now if you have some real criticism then fine tell the development team, I
> hope they all (like they should) be receptive to constructive criticism, the
> criticism you are currently leveling is totally ludicrous,
What, all the individual points I have made are all ludicrous? Fancy that.
> Saying things like <quot>The PHP interpreter is nowhere near well-written
> enough for this feature to be of any use at all.</quot>
That's taken out of context. The PHP code is fine for doing what it
usually does. If you try to use it for something unusual, i.e. safe_mode,
then it is not good at this. The PHP developers said as much on this list
today!
> You have shown a blatient disrespect for them and no wonder your
> suggestions are getting nowhere.
If the developers are so masterful and wise, I am sure they are perfectly
capable of extracting reason from insult in my emails. I said as much in
the first email. Right at the top. The first PHP developer to reply did
very well.