Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 13:59:42 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.dev 
Request: Send a blank email to php-dev+get-32368@lists.php.net to get a copy of this message
Johan Andersson <johan@andersson.net> wrote: > You said to me that you didn't use htmlentities in url's No I didn't. > I think you have to look some further in the manual about the htmlentities, No. I have read the manual. I have read the source. I know what both of these functions do - considerably better than you do, it seems. > And using it in URLs in _NOT_ defensive programming! Using it *everywhere* is defensive programming. The point I think you are missing is - yes, it's a URL. But it is *in a web page*. So, it not only needs to be url-encoded, it needs to be HTML-encoded too. It may be that as it happens HTML-encoding of the output of 'urlencode' will output the same as its input, but this does not mean it is not a good idea to do it anyway. And, in the slightly more complex case of multiple parameters in the URL, you have to make the choice of either writing an HTML-encoded URL by hand, or writing a URL and getting PHP to HTML-encode it for you. TTOTD: Not a lot of people realise that: <a href="foo.php?a=1&b=2"> is wrong. It should be: <a href="foo.php?a=1&amp;b=2"> > Characters with ascii numbers 0-27, 127-255 should be replaced with > [%][ascii number in hex] > like %20 is space, space is ascii 32, which has the hexadecimal value 20. Wrong. This is not what urlencode does at all. I suggest you go and read the PHP manual page on it - it is complete and correct. > And hey.. I just want to help you.. saw you wrote something incorrect and I > just wanted to be nice and explain why I think you wrote something > incorrect.. You have failed to find anything incorrect that I have written. Your explanation is wrong. I appreciate your efforts but they have not been particularly helpful thus far.

« previous php.dev (#32368) next »