Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 12:05:25 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.dev 
Request: Send a blank email to php-dev+get-32349@lists.php.net to get a copy of this message
Jon Ribbens writes: > Lars Torben Wilson <torben@php.net> wrote: > > > How are people supposed to know how to program PHP? Are they allowed to > > > go looking through the source code, to find hacky tricks that work in > > > today's CVS tree, and then complain when they don't work tomorrow? > > > > Certainly. It's their own damn fault if they get bitten, same as it is > > my own fault if I write code depending on any undocumented feature in > > gcc. > > Exactly! This is my whole damn point. It is not possible, for example, > to write file upload code without either (a) being insecure, or > (b) relying on undocumented features. Since you and I both agree that As has been noted before, fixes are already in the manual, and more are being worked on. And what undocumented features are required to handle file uploads safely? I don't see the agreement here. > The main issue anyway is access to CGI variables. I hope no-one is going > to claim that these are not frequently accessed. Probably not, no. > > I have many more lines of PHP which are not concerned with HTML than I > > have lines which are. If I need HTML, I can simply drop out of PHP > > into HTML and do it there. With an editor or something. > > You don't need htmlentities() with static HTML - only when you're outputting > generated HTML. In which case you have to do it in the PHP section. In a large project it can become a moot point as often, modular systems don't sanction output from modules. However, again it is simply a matter of being aware of what you're coding in PHP, as in any other language. I'm not claiming that htmlentities() isn't used; I'm claiming that this ridiculously inflammatory approach to public education is not helping matters. > > You haven't the right to judge others on the value of their > > volunteer work until your own efforts to improve said work can be > > demonstrated to match those of the people you judge. > > I can't cook, but I can tell burnt food when I eat it. Even if that were the point, that's rationalization, not justification. The point is that you're slagging people left, right, and center, with little regard to common courtesy, and not lifting a finger to help *solve* the problem. You have some valid points. That doesn't justify the manner. > Besides which, I don't claim the right to judge anything. I'm simply > pointing out a few observations. You can do something about them or > ignore them as you will. I can't force people to do the right thing. > They have to decide to by themselves. No, you were not 'simply pointing out a few observations'. Witness: You people don't deserve me being nice to you. Be that as it may, this is a sarcasm-free posting. Rejoice. Cheers Jon Hi-ho. And unless you missed it, no-one here is ignoring anything. Several commits have been made to both the manual and the source--this is *not* to say the work is finished, mind--and people have been looking at different ways to ameliorate the problem. Again, the problem doesn't lie so much with the message as with the delivery. -- +----------------------------------------------------------------+ |Torben Wilson <torben@php.net> Netmill iTech| |http://www.coastnet.com/~torben http://www.netmill.fi| |Ph: 1 250 383-9735 torben@netmill.fi| +----------------------------------------------------------------+

« previous php.dev (#32349) next »