Re: Security Issues

From: Date: Mon, 30 Jul 2001 08:02:38 +0000
Subject: Re: Security Issues
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-61454@lists.php.net to get a copy of this message
UNSUBSCRIBE ME PLEASE!!!!!!!!!!!!!! Phil Driscoll schrieb: > On Saturday 28 July 2001 20:52, Zeev Suraski wrote: > > a rebuf to each of my arguments :) > > Rather than prolong the agony, my point is that in all the cases where a > malicious user has the chance to inject a dodgy variable, the code must > normally have a logic path which allows the code to pass through an undefined > usage of that variable. In testing the code with E_NOTICE on, a warning > message will be displayed. The warning message could be beefed up to scare > the user a bit more, but for me it is this that hits the nail on the head. > > I can assure you that the monkeys will screw things up whowever you change > the code :) > > That said, It's easy to live with the proposal, especially with the > import_globals() functions. > > Cheers > -- > Phil Driscoll > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#61454) next »