Re: Security techniques
| From: | Rasmus Lerdorf | Date: | Sun, 29 Jul 2001 19:06:30 +0000 |
| Subject: | Re: Security techniques | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61388@lists.php.net to get a copy of this message | ||
> Have PHP reject (fail to process, die, whatever) a hit that is
> anomalous. Definitions of anomalous:
>
> 1. GET variables set while METHOD != GET
>
> i.e.
> <form action="foo.php?x=1" method=POST>
> ...
> </form>
Huh? I use this all the time in my apps. There is absolutely nothing
wrong with having both GET and POST method variables at the same time.
Disallowing this would break almost every app I have ever written.
> 2. when a uploaded file fails is_uploaded_file().
>
> I felt bad when I saw is_uploaded_file() introduced - it is such a
> cheezy function call; people shouldn't even have to call it themselves,
> and I can imagine no situation (except for laziness) that you would not
> call it.
In practise people simply call move_uploaded_file() which performs this
check.
-Rasmus