Re: PHP File Upload Security Hole - Still No Fix?
| From: | Lars Torben Wilson | Date: | Wed, 06 Sep 2000 12:05:25 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32349@lists.php.net to get a copy of this message | ||
Jon Ribbens writes:
> Lars Torben Wilson <torben@php.net> wrote:
> > > How are people supposed to know how to program PHP? Are they allowed to
> > > go looking through the source code, to find hacky tricks that work in
> > > today's CVS tree, and then complain when they don't work tomorrow?
> >
> > Certainly. It's their own damn fault if they get bitten, same as it is
> > my own fault if I write code depending on any undocumented feature in
> > gcc.
>
> Exactly! This is my whole damn point. It is not possible, for example,
> to write file upload code without either (a) being insecure, or
> (b) relying on undocumented features. Since you and I both agree that
As has been noted before, fixes are already in the manual, and more
are being worked on. And what undocumented features are required to
handle file uploads safely? I don't see the agreement here.
> The main issue anyway is access to CGI variables. I hope no-one is going
> to claim that these are not frequently accessed.
Probably not, no.
> > I have many more lines of PHP which are not concerned with HTML than I
> > have lines which are. If I need HTML, I can simply drop out of PHP
> > into HTML and do it there. With an editor or something.
>
> You don't need htmlentities() with static HTML - only when you're outputting
> generated HTML. In which case you have to do it in the PHP section.
In a large project it can become a moot point as often, modular
systems don't sanction output from modules. However, again it is
simply a matter of being aware of what you're coding in PHP, as in any
other language. I'm not claiming that htmlentities() isn't used; I'm
claiming that this ridiculously inflammatory approach to public
education is not helping matters.
> > You haven't the right to judge others on the value of their
> > volunteer work until your own efforts to improve said work can be
> > demonstrated to match those of the people you judge.
>
> I can't cook, but I can tell burnt food when I eat it.
Even if that were the point, that's rationalization, not
justification. The point is that you're slagging people left, right,
and center, with little regard to common courtesy, and not lifting a
finger to help *solve* the problem. You have some valid points. That
doesn't justify the manner.
> Besides which, I don't claim the right to judge anything. I'm simply
> pointing out a few observations. You can do something about them or
> ignore them as you will. I can't force people to do the right thing.
> They have to decide to by themselves.
No, you were not 'simply pointing out a few observations'. Witness:
You people don't deserve me being nice to you. Be that as it may,
this is a sarcasm-free posting. Rejoice.
Cheers
Jon
Hi-ho.
And unless you missed it, no-one here is ignoring anything. Several
commits have been made to both the manual and the source--this is
*not* to say the work is finished, mind--and people have been looking
at different ways to ameliorate the problem.
Again, the problem doesn't lie so much with the message as with the
delivery.
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+