Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Thu, 07 Sep 2000 14:06:51 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32548@lists.php.net to get a copy of this message | ||
Jon Evans <jevans@red-net.co.uk> wrote:
> I think the point is that a malicious user could form such a request and
> use it to break your script, no?
I don't think there is any particular security issue here, because
what it looks like PHP is doing is truncating at the first null
byte - and the attacker could have just truncated the string there
before sending it anyway.
The problem is that users may expect sending binary data to work,
and be confused and waste time debugging when it doesn't. Making
it binary safe would be nice, documenting that it isn't would be
sufficient.