Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 20:30:47 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32241@lists.php.net to get a copy of this message
Peter Korsgaard wrote: > On Tue, 5 Sep 2000, Jon Ribbens wrote: > > I bet there are thousands of scripts out there that rely on variables > > being unset at the start of their execution, that could be persuaded > > to do bad things by setting the variables via CGI variables. I bet there > > are thousands more which have bugs due to confusion as to where a variable > > came from. > > Couldn't we instead implement warnings as in gcc which tell you if you use > an unitialised variable? That way evil hackers couldn't overwrite our > trusted variables. Warning level E_ALL does just this, but the problem wasn't an uninitialized variable. It was initialized, with dangeous data.... (see HTTP_*_VARS thread) -Bop -- Brought to you from boop!, the dual boot Linux/Win95 Compaq Presario 1625 laptop, currently running RedHat 6.1. Your bopping may vary.

« previous php.dev (#32241) next »