Re: PHP File Upload Security Hole - Still No Fix?
| From: | Hellekin O. Wolf | Date: | Wed, 06 Sep 2000 14:40:07 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32384@lists.php.net to get a copy of this message | ||
Jon Ribbens wrote:
>
> <html><head><title>Foo</title></head>
> <body>
> <a href="foo?a=1&b=1">a=1&b=1</a><br>
> <a href="foo?a=1&b=1">a=1&amp;b=1</a><br>
> <a href="foo?a=1£=1">a=1&pound=1</a><br>
> <a href="foo?a=1&pound=1">a=1&amp;pound=1</a><br>
> </body></html>
>
*** Neat... Indeed it makes a difference. £ is not £ AFAIK.
I've been reading the whole thread with interest.
Many points have been raised that are important but they're so much
surrounded by dirt that maybe you Jon, as you started this whole
comment, should filter it and come with some (objective) synthesis that
could encourage other people to pay attention to what you have to say.
That said, I'm always surprised with comments such as "this is bad style
programming" that takes for granted that every programmer knows "how to
program well". I'm sorry to tell you guyz, everybody starts from zero
and acquire experience through learning and practiving. Good coding
style is not obvious and indeed seem to depend on the programmer's
background also.
Such a discussion is important and may be helpful for most of us, PHP
programmers, experts or beginners, to learn how to avoid Bad Coding
Practice (TM).
can't we all get along ? ;-)
hellekin