Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 22:16:23 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32469@lists.php.net to get a copy of this message | ||
Zeev Suraski <zeev@zend.com> wrote:
> The difference is in the approach. You started off by whining. If that's
> what you wish to do, I'll appreciate it if you do it off the mailing list.
Well, darn it, what's the point of that?
> Constructive criticism is something completely different from whining or
> bashing others.
Both can be done simultaneously, however. There seem to be a lot of people
here failing to notice this. You can ignore me if you like, but the points
I am raising won't go away.
> > > (binary safety to avoid buffer overflows,
> >
> >I found this interesting undocumented feature while looking at all this
> >file upload stuff:
> >
> > /* FIXME: XXX: not binary safe, discards returned length */
>
> It seems to me more and more that you're not serious - all you seem to do
> all the time is whine.
That's funny. I thought I just pointed out a bug. What's your definition
of 'whine' then? Someone who doesn't agree with you?
You said that PHP 4 had binary safety, I mentioned out that in the very small
amount of PHP 4 source I have read, I can immediately point to an important
instance where that simply isn't true. If you don't want me to disagree with
you, choose what you say more carefully.
> As for the issue itself - I'm not sure if we're expecting binary data here
> (I'm pretty sure we're not).
I'm sure you could guess that I would say this but: if this is the case,
then you need to document it.
> Considering the huge userbase and the fact nobody complained so far, it
> sounds like you're even whining about the wrong things.
You brought the issue up, not me.
> Trust me, I know exactly what my patch does and what it doesn't do (and I
> knew that before you pointed it out so wisely). Security wise, it doesn't
> do much.
So why did you post it as a reply to the advisory on BUGTRAQ?
> >Excellent. Put it in the manual! Make the next release have it turned off
> >by default! For sure, put in really large letters in the release notes
> >what you've done, but new users and new scripts should not continue to be
> >written using register_globals.
>
> Breaking 99.9% of the scripts in the world isn't my idea of fun,
You have such little faith in your users that you don't think there is any
way you can get them to realise that the default has changed, and to change
it back if they need it? As a PHP user, I should be insulted.
> >Make them keywords. Use a special '%' syntax. Whatever. What you say here
> >is simply untrue.
>
> I might be funny here, but I kinda trust what I have to say about the
> subject more than I trust what you have to say about the subject. Using
> functions to access globals is extremely slow, and thus completely silly
> (c). Use one letter variables if you wish, just don't use functions.
If you say functions are slower, then fine, I believe you. Which is why
I listed several alternatives to achieve the same effect above. But you
seem to have ignored that.
> If that tone is going to continue, this is the last time I'll converse with
> you. I don't see why this should be the case, but that's your choice.
It's your loss more than mine. But again, this post is guaranteed 100%
pure sweetness-and-light. Or your money back.