Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 10:17:51 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8  Groups: php.dev 
Request: Send a blank email to php-dev+get-32337@lists.php.net to get a copy of this message
Ron Chmara <ron@opus1.com> wrote: > > Do you not understand what documentation is and does? Documentation > > is a guarantee of what works, and what will work in the future. How should > > I know the answers to these questions? > > Documentation is no guarantee. :-) In which case it is no documentation. How are people supposed to know how to program PHP? Are they allowed to go looking through the source code, to find hacky tricks that work in today's CVS tree, and then complain when they don't work tomorrow? > Indeed, PHP has gone _much_ further than most other languages by having > real-time, 24x7, documentation correction/addition avialable to > *every* user who wishes to contribute. This is great, for people to add examples and tips. It is no use for providing documentation of what the functions do. > > I would only suggest that 3 or 4 of the most frequently used functions > > would be given short names. I would recommend, maybe: htmlentities, > > Never used it. If you are writing code to produce HTML output, as I think I can safely assume most PHP code is, and you have never used htmlentities, then your code is almost certainly completely broken. > > urlencode, > > Used it twice in over 120K of code lines. Ditto, if you have written code to generate URLs. > > addslashes > > Used it 15 times in the same code base. I can only assume that you are not using databases then, or else, your code is totally insecure. > I'm trying to point out that short names and their viability depend on > the functions which are used the _most_, and who uses which functions > _most_ varies wildy. I don't believe this. PHP generates HTML. If you are generating HTML, you *will* be using the 'htmlentities' function a lot. I think a very large number of people, maybe even most, use PHP with SQL databases. > If we erred on the side of Perl, where massive amounts of short names > lead to the "obsfusication" mockery of the language, we make PHP less > usable for code portability/reading/maintenance reasons. It's no better to err in the other direction though. > You see, I do a _lot_ of maintenance coding. Most coding is maintenance > coding, not code authoring, so the best thing for a coding house is to use > lots of longer syntax, to increase code readability. It is a small price to pay to say that "if you learn PHP, you need to know the following 3 functions". I am not in any way advocating large numbers of short-named functions. Cheers Jon

« previous php.dev (#32337) next »