Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Thu, 07 Sep 2000 11:48:50 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.dev 
Request: Send a blank email to php-dev+get-32530@lists.php.net to get a copy of this message
On Thu, Sep 07, 2000 at 12:28:59PM +0100, Jon Ribbens wrote: > Thies Arntzen <thies@digicol.de> wrote: > > please "enligthen" me on how to pass binary data (namely data > > that contains '\0') to a cgi. > > foo.php?data=hello%00there > > > - have you read (& understood) the related rfc? > > Yes. > > > - have you read (& understood) the source you're complaining about? > > I think so. Hence my enquiry. even though the impact is minimal (no user has ever complained) i have to admit that you are right, and this should be changed. we do not support \0 in names of variables, but we do support binary content and should allow \0 in cgi-data (there's no technical reason not to). -but- i'm pretty sure you (as a decent person) would agree that no browser-generated request would ever contain %00 in the URL, wouldn't you? (i've never seen a -NULL- key on a keyboard, no widely used encoding has \0 bytes in a character stream - for obvious reasons;) tc > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- Thies C. Arntzen "One Big-Mac, Small Fries and a Coke!" Digital Collections Phone +49 40 235350 Fax +49 40 23535180 Hammerbrookstr. 93 20097 Hamburg / Germany

« previous php.dev (#32530) next »