Re: Quick Code Audit
| From: | Lars Torben Wilson | Date: | Wed, 06 Sep 2000 10:21:58 +0000 |
| Subject: | Re: Quick Code Audit | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32339@lists.php.net to get a copy of this message | ||
Stanislav Malyshev writes:
> LTW>> Perhaps a more formal introduction and reference on programming PHP 4
> LTW>> internals would be good: give folks who are writing extensions or
>
> Security-wise, PHP internals (like Zend engine) is pretty safe, you can't
> break anything unless you've done something stupid on previous layers,
> like mixing zval's, modifying convert_..._ex result or something like
> that. Most real "security" is in layers like safe_mode layer and fopen
> wrappers and probably network code, which are pretty indifferent to Zend
> internals.
> --
> Stanislav Malyshev stas@zend.com http://www.zend.com/
>
> +972-3-6139665 ext.106
There are things that should be looked at in userland, and things that
should be looked at in PHPland. If someone's gonna write something
(maybe an extension, maybe something like file upload), they should
know what to look out for. The internal structure probably doesn't
protect the author from all possible mistakes. Those are what should,
at the very least, be documented. If it is documented somewhere, let
me know and I'll look at adding it to the Appendices.
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+