Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Evans | Date: | Thu, 07 Sep 2000 13:29:12 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32544@lists.php.net to get a copy of this message | ||
Hi Thies,
On Thu, Sep 07, 2000 at 01:48:50PM +0200, Thies Arntzen wrote:
> -but- i'm pretty sure you (as a decent person) would agree
> that no browser-generated request would ever contain %00 in
> the URL, wouldn't you? (i've never seen a -NULL- key on a
> keyboard, no widely used encoding has \0 bytes in a character
> stream - for obvious reasons;)
I think the point is that a malicious user could form such a request and
use it to break your script, no?
Jon.
--
Jon Evans / Red Internet Ltd. / +44 1869 337977