Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 12:24:19 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32350@lists.php.net to get a copy of this message | ||
Lars Torben Wilson <torben@php.net> wrote:
> As has been noted before, fixes are already in the manual, and more
> are being worked on. And what undocumented features are required to
> handle file uploads safely? I don't see the agreement here.
HTTP_POST_FILES
> The point is that you're slagging people left, right, and center, with
> little regard to common courtesy,
Sorry, in my opinion after the two posts made by the PHP developers to
BUGTRAQ, you deserve whatever you get.
> and not lifting a finger to help *solve* the problem.
This has been repeatedly claimed, but nobody has yet explained what
I am supposed to be doing to help.