Re: PHP File Upload Security Hole - Still No Fix?
| From: | Ron Chmara | Date: | Tue, 05 Sep 2000 20:30:47 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32241@lists.php.net to get a copy of this message | ||
Peter Korsgaard wrote:
> On Tue, 5 Sep 2000, Jon Ribbens wrote:
> > I bet there are thousands of scripts out there that rely on variables
> > being unset at the start of their execution, that could be persuaded
> > to do bad things by setting the variables via CGI variables. I bet there
> > are thousands more which have bugs due to confusion as to where a variable
> > came from.
>
> Couldn't we instead implement warnings as in gcc which tell you if you use
> an unitialised variable? That way evil hackers couldn't overwrite our
> trusted variables.
Warning level E_ALL does just this, but the problem wasn't an uninitialized
variable. It was initialized, with dangeous data.... (see HTTP_*_VARS thread)
-Bop
--
Brought to you from boop!, the dual boot Linux/Win95 Compaq Presario 1625
laptop, currently running RedHat 6.1. Your bopping may vary.