Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 10:17:51 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32337@lists.php.net to get a copy of this message | ||
Ron Chmara <ron@opus1.com> wrote:
> > Do you not understand what documentation is and does? Documentation
> > is a guarantee of what works, and what will work in the future. How should
> > I know the answers to these questions?
>
> Documentation is no guarantee. :-)
In which case it is no documentation.
How are people supposed to know how to program PHP? Are they allowed to
go looking through the source code, to find hacky tricks that work in
today's CVS tree, and then complain when they don't work tomorrow?
> Indeed, PHP has gone _much_ further than most other languages by having
> real-time, 24x7, documentation correction/addition avialable to
> *every* user who wishes to contribute.
This is great, for people to add examples and tips. It is no use for
providing documentation of what the functions do.
> > I would only suggest that 3 or 4 of the most frequently used functions
> > would be given short names. I would recommend, maybe: htmlentities,
>
> Never used it.
If you are writing code to produce HTML output, as I think I can safely
assume most PHP code is, and you have never used htmlentities, then your
code is almost certainly completely broken.
> > urlencode,
>
> Used it twice in over 120K of code lines.
Ditto, if you have written code to generate URLs.
> > addslashes
>
> Used it 15 times in the same code base.
I can only assume that you are not using databases then, or else, your
code is totally insecure.
> I'm trying to point out that short names and their viability depend on
> the functions which are used the _most_, and who uses which functions
> _most_ varies wildy.
I don't believe this. PHP generates HTML. If you are generating HTML, you
*will* be using the 'htmlentities' function a lot. I think a very large
number of people, maybe even most, use PHP with SQL databases.
> If we erred on the side of Perl, where massive amounts of short names
> lead to the "obsfusication" mockery of the language, we make PHP less
> usable for code portability/reading/maintenance reasons.
It's no better to err in the other direction though.
> You see, I do a _lot_ of maintenance coding. Most coding is maintenance
> coding, not code authoring, so the best thing for a coding house is to use
> lots of longer syntax, to increase code readability.
It is a small price to pay to say that "if you learn PHP, you need to
know the following 3 functions". I am not in any way advocating large
numbers of short-named functions.
Cheers
Jon