Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 10:54:14 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9  Groups: php.dev 
Request: Send a blank email to php-dev+get-32342@lists.php.net to get a copy of this message
Jon Ribbens writes: > In which case it is no documentation. > > How are people supposed to know how to program PHP? Are they allowed to > go looking through the source code, to find hacky tricks that work in > today's CVS tree, and then complain when they don't work tomorrow? Certainly. It's their own damn fault if they get bitten, same as it is my own fault if I write code depending on any undocumented feature in gcc. And so much the better if they find something wrong and fix it. Same as with many other languages. 'Allowed' is a tricky word in a free world. > > Indeed, PHP has gone _much_ further than most other languages by having > > real-time, 24x7, documentation correction/addition avialable to > > *every* user who wishes to contribute. > > This is great, for people to add examples and tips. It is no use for > providing documentation of what the functions do. Quite the contrary. That's what many use it for, but that's a different issue. :) Anyone, meaning *anyone* (even you, Jon), can look at the code, figure out what a function (or operator, or feature, or whatever) does, and add a note regarding it. This is simply to make it easier for folks to add things to the documentation, without them having to learn XML, DocBook, and all the associated Jade-wrestling that can go along with the manual's upkeep. These submissions are then looked over (at some point, when there's time; remember, this is volunteer* work, here) by manual authors, checked for validity, and if necessary, added to the manual. > > > I would only suggest that 3 or 4 of the most frequently used functions > > > would be given short names. I would recommend, maybe: htmlentities, > > > > Never used it. > > If you are writing code to produce HTML output, as I think I can safely > assume most PHP code is, and you have never used htmlentities, then your > code is almost certainly completely broken. Would you care to elaborate? Some examples to prove your point would go down real good right about now. > > > urlencode, > > > > Used it twice in over 120K of code lines. > > Ditto, if you have written code to generate URLs. Mm. Unless you build them by hand. Jon, I've been coding PHP for some years now, and while these functions certainly get used, you're completely overstating the number of lines of code on which they turn up. > > I'm trying to point out that short names and their viability depend on > > the functions which are used the _most_, and who uses which functions > > _most_ varies wildy. > > I don't believe this. PHP generates HTML. If you are generating HTML, you > *will* be using the 'htmlentities' function a lot. I think a very large > number of people, maybe even most, use PHP with SQL databases. I have many more lines of PHP which are not concerned with HTML than I have lines which are. If I need HTML, I can simply drop out of PHP into HTML and do it there. With an editor or something. Hyperbole again. > > You see, I do a _lot_ of maintenance coding. Most coding is maintenance > > coding, not code authoring, so the best thing for a coding house is to use > > lots of longer syntax, to increase code readability. > > It is a small price to pay to say that "if you learn PHP, you need to > know the following 3 functions". I am not in any way advocating large > numbers of short-named functions. > > Cheers > > > Jon * - We are volunteers, Jon. We do this for our own reasons. Not yours. You haven't the right to judge others on the value of their volunteer work until your own efforts to improve said work can be demonstrated to match those of the people you judge. Until such a time, you are simply insulting the members of the team. Submit a Bug Report, add a Note to the manual, fix the code (yes, I know it's distasteful to you; how convenient), or do something besides hurt people. Yes, I know you think you're helping people. I'm glad you don't work for the Red Cross. -- +----------------------------------------------------------------+ |Torben Wilson <torben@php.net> Netmill iTech| |http://www.coastnet.com/~torben http://www.netmill.fi| |Ph: 1 250 383-9735 torben@netmill.fi| +----------------------------------------------------------------+

« previous php.dev (#32342) next »