Re: PHP File Upload Security Hole - Still No Fix?
| From: | Lee Willis | Date: | Wed, 06 Sep 2000 13:00:41 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32355@lists.php.net to get a copy of this message | ||
Jon Ribbens <jon+php-dev@unequivocal.co.uk> writes:
> André Langhorst <waldschrott@php.net> wrote:
> > > echo '<a
> > > href="product.php?id=',htmlentities(urlencode($row['ID'])),'>';
> > >
> > > (This is an excellent example of why I prefer H() and U() [;-)]
> >
> > you´re designing crappy databases
>
> Sorry, my database is crappy because it has a field named 'ID'? I don't
> quite follow.
No it's crappy because if you designed your database properly , ie.
- Made your products referenced by a numeric unique ID
- Enforced that numericness by making the column an int() column in the
database
then you would know that when the ID comes out it will be numeric only
and you don't have to urlencode(), or htmlentities() it, it's just a
number, your database will enforce that for you ...
> > you don´t need to convert every single value which comes out of the
> > database! theres a thing called database design.
>
> And good database design says store all your values HTML-encoded?
> News to me.
No, see above, he said you don't have to convert everything!, some
things will have to be encoded certainly, but not "everything".
Lee
--