Re: Security Issues
| From: | Phil Driscoll | Date: | Sun, 29 Jul 2001 08:04:01 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61351@lists.php.net to get a copy of this message | ||
On Saturday 28 July 2001 20:52, Zeev Suraski wrote:
a rebuf to each of my arguments :)
Rather than prolong the agony, my point is that in all the cases where a
malicious user has the chance to inject a dodgy variable, the code must
normally have a logic path which allows the code to pass through an undefined
usage of that variable. In testing the code with E_NOTICE on, a warning
message will be displayed. The warning message could be beefed up to scare
the user a bit more, but for me it is this that hits the nail on the head.
I can assure you that the monkeys will screw things up whowever you change
the code :)
That said, It's easy to live with the proposal, especially with the
import_globals() functions.
Cheers
--
Phil Driscoll