Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 14:38:38 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32382@lists.php.net to get a copy of this message | ||
Johan Andersson <johan@andersson.net> wrote:
> The first time I really got into that with & in url's were in 1 year
> ago.. and I know exactly how it works and what it does.
You clearly don't - otherwise you wouldn't be disagreeing with me.
> I asked for you answer on WHY someone should do like that and why it would
> be safer (even though the browser encodes it).
The browser *decodes* it, not *encodes* it. It's not safer it just
*doesn't work* if you do it wrong (if, and only if, the output happens
to be a valid entity, which you cannot guarantee it won't be).
Try the example and you will understand. Until you do, you won't.