Re: Security Issues
| From: | Ramsi Sras | Date: | Mon, 30 Jul 2001 08:02:38 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61454@lists.php.net to get a copy of this message | ||
UNSUBSCRIBE ME PLEASE!!!!!!!!!!!!!!
Phil Driscoll schrieb:
> On Saturday 28 July 2001 20:52, Zeev Suraski wrote:
>
> a rebuf to each of my arguments :)
>
> Rather than prolong the agony, my point is that in all the cases where a
> malicious user has the chance to inject a dodgy variable, the code must
> normally have a logic path which allows the code to pass through an undefined
> usage of that variable. In testing the code with E_NOTICE on, a warning
> message will be displayed. The warning message could be beefed up to scare
> the user a bit more, but for me it is this that hits the nail on the head.
>
> I can assure you that the monkeys will screw things up whowever you change
> the code :)
>
> That said, It's easy to live with the proposal, especially with the
> import_globals() functions.
>
> Cheers
> --
> Phil Driscoll
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net