Re: PHP File Upload Security Hole - Still No Fix?
| From: | Thies Arntzen | Date: | Thu, 07 Sep 2000 11:48:50 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32530@lists.php.net to get a copy of this message | ||
On Thu, Sep 07, 2000 at 12:28:59PM +0100, Jon Ribbens wrote:
> Thies Arntzen <thies@digicol.de> wrote:
> > please "enligthen" me on how to pass binary data (namely data
> > that contains '\0') to a cgi.
>
> foo.php?data=hello%00there
>
> > - have you read (& understood) the related rfc?
>
> Yes.
>
> > - have you read (& understood) the source you're complaining about?
>
> I think so. Hence my enquiry.
even though the impact is minimal (no user has ever
complained) i have to admit that you are right, and this
should be changed. we do not support \0 in names of
variables, but we do support binary content and should allow
\0 in cgi-data (there's no technical reason not to).
-but- i'm pretty sure you (as a decent person) would agree
that no browser-generated request would ever contain %00 in
the URL, wouldn't you? (i've never seen a -NULL- key on a
keyboard, no widely used encoding has \0 bytes in a character
stream - for obvious reasons;)
tc
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Thies C. Arntzen "One Big-Mac, Small Fries and a Coke!"
Digital Collections Phone +49 40 235350 Fax +49 40 23535180
Hammerbrookstr. 93 20097 Hamburg / Germany