Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 13:59:42 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32368@lists.php.net to get a copy of this message | ||
Johan Andersson <johan@andersson.net> wrote:
> You said to me that you didn't use htmlentities in url's
No I didn't.
> I think you have to look some further in the manual about the htmlentities,
No. I have read the manual. I have read the source. I know what both
of these functions do - considerably better than you do, it seems.
> And using it in URLs in _NOT_ defensive programming!
Using it *everywhere* is defensive programming.
The point I think you are missing is - yes, it's a URL.
But it is *in a web page*. So, it not only needs to be url-encoded,
it needs to be HTML-encoded too. It may be that as it happens
HTML-encoding of the output of 'urlencode' will output the same as its
input, but this does not mean it is not a good idea to do it anyway.
And, in the slightly more complex case of multiple parameters in the URL,
you have to make the choice of either writing an HTML-encoded URL
by hand, or writing a URL and getting PHP to HTML-encode it for you.
TTOTD: Not a lot of people realise that:
<a href="foo.php?a=1&b=2">
is wrong. It should be:
<a href="foo.php?a=1&b=2">
> Characters with ascii numbers 0-27, 127-255 should be replaced with
> [%][ascii number in hex]
> like %20 is space, space is ascii 32, which has the hexadecimal value 20.
Wrong. This is not what urlencode does at all. I suggest you go and read
the PHP manual page on it - it is complete and correct.
> And hey.. I just want to help you.. saw you wrote something incorrect and I
> just wanted to be nice and explain why I think you wrote something
> incorrect..
You have failed to find anything incorrect that I have written. Your
explanation is wrong. I appreciate your efforts but they have not been
particularly helpful thus far.