Re: Security techniques
| From: | Ramsi Sras | Date: | Mon, 30 Jul 2001 08:07:02 +0000 |
| Subject: | Re: Security techniques | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61484@lists.php.net to get a copy of this message | ||
UNSUBSCRIBE ME PLEASE!!!!!!!!!!!!!!
Rasmus Lerdorf schrieb:
> > Have PHP reject (fail to process, die, whatever) a hit that is
> > anomalous. Definitions of anomalous:
> >
> > 1. GET variables set while METHOD != GET
> >
> > i.e.
> > <form action="foo.php?x=1" method=POST>
> > ...
> > </form>
>
> Huh? I use this all the time in my apps. There is absolutely nothing
> wrong with having both GET and POST method variables at the same time.
> Disallowing this would break almost every app I have ever written.
>
> > 2. when a uploaded file fails is_uploaded_file().
> >
> > I felt bad when I saw is_uploaded_file() introduced - it is such a
> > cheezy function call; people shouldn't even have to call it themselves,
> > and I can imagine no situation (except for laziness) that you would not
> > call it.
>
> In practise people simply call move_uploaded_file() which performs this
> check.
>
> -Rasmus
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net