Re: PHP File Upload Security Hole - Still No Fix?
| From: | Lars Torben Wilson | Date: | Wed, 06 Sep 2000 10:54:14 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32342@lists.php.net to get a copy of this message | ||
Jon Ribbens writes:
> In which case it is no documentation.
>
> How are people supposed to know how to program PHP? Are they allowed to
> go looking through the source code, to find hacky tricks that work in
> today's CVS tree, and then complain when they don't work tomorrow?
Certainly. It's their own damn fault if they get bitten, same as it is
my own fault if I write code depending on any undocumented feature in
gcc. And so much the better if they find something wrong and fix
it. Same as with many other languages. 'Allowed' is a tricky word in a
free world.
> > Indeed, PHP has gone _much_ further than most other languages by having
> > real-time, 24x7, documentation correction/addition avialable to
> > *every* user who wishes to contribute.
>
> This is great, for people to add examples and tips. It is no use for
> providing documentation of what the functions do.
Quite the contrary. That's what many use it for, but that's a
different issue. :) Anyone, meaning *anyone* (even you, Jon), can look
at the code, figure out what a function (or operator, or feature, or
whatever) does, and add a note regarding it. This is simply to make it
easier for folks to add things to the documentation, without them
having to learn XML, DocBook, and all the associated Jade-wrestling
that can go along with the manual's upkeep. These submissions are then
looked over (at some point, when there's time; remember, this is
volunteer* work, here) by manual authors, checked for validity, and if
necessary, added to the manual.
> > > I would only suggest that 3 or 4 of the most frequently used functions
> > > would be given short names. I would recommend, maybe: htmlentities,
> >
> > Never used it.
>
> If you are writing code to produce HTML output, as I think I can safely
> assume most PHP code is, and you have never used htmlentities, then your
> code is almost certainly completely broken.
Would you care to elaborate? Some examples to prove your point would
go down real good right about now.
> > > urlencode,
> >
> > Used it twice in over 120K of code lines.
>
> Ditto, if you have written code to generate URLs.
Mm. Unless you build them by hand. Jon, I've been coding PHP for some
years now, and while these functions certainly get used, you're
completely overstating the number of lines of code on which they turn
up.
> > I'm trying to point out that short names and their viability depend on
> > the functions which are used the _most_, and who uses which functions
> > _most_ varies wildy.
>
> I don't believe this. PHP generates HTML. If you are generating HTML, you
> *will* be using the 'htmlentities' function a lot. I think a very large
> number of people, maybe even most, use PHP with SQL databases.
I have many more lines of PHP which are not concerned with HTML than I
have lines which are. If I need HTML, I can simply drop out of PHP
into HTML and do it there. With an editor or something.
Hyperbole again.
> > You see, I do a _lot_ of maintenance coding. Most coding is maintenance
> > coding, not code authoring, so the best thing for a coding house is to use
> > lots of longer syntax, to increase code readability.
>
> It is a small price to pay to say that "if you learn PHP, you need to
> know the following 3 functions". I am not in any way advocating large
> numbers of short-named functions.
>
> Cheers
>
>
> Jon
* - We are volunteers, Jon. We do this for our own reasons. Not
yours. You haven't the right to judge others on the value of their
volunteer work until your own efforts to improve said work can be
demonstrated to match those of the people you judge. Until such a
time, you are simply insulting the members of the team. Submit a Bug
Report, add a Note to the manual, fix the code (yes, I know it's
distasteful to you; how convenient), or do something besides hurt
people. Yes, I know you think you're helping people. I'm glad you
don't work for the Red Cross.
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+