Re: Re: PHP-4.0.7RC1

From: Date: Sat, 18 Aug 2001 00:51:13 +0000
Subject: Re: Re: PHP-4.0.7RC1
References: 1  Groups: php.dev php.qa 
Request: Send a blank email to php-dev+get-63561@lists.php.net to get a copy of this message
Relying on initialization by the system instead of doing it by hand is bad. What if somebody then includes your file into something else, but has used that variable, but their final value is usually 0, except when it's not... Then, your code works for a while and then inexplicably breaks. Always initialize variables. -- WARNING richard@zend.com address is an endangered species -- Use ceo@l-i-e.com Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm Volunteer a little time: http://chatmusic.com/volunteer.htm ----- Original Message ----- From: Stanislav Malyshev <stas@zend.com> To: Cynic <cynic@mail.cz> Cc: Zeev Suraski <zeev@zend.com>; <php-qa@lists.php.net>; PHP Development <php-dev@lists.php.net> Sent: Friday, August 17, 2001 11:33 AM Subject: Re: [PHP-QA] Re: PHP-4.0.7RC1 > C>> if('foo' == $x){ > C>> $secure = true; > C>> } > C>> ... > C>> if($secure){ > C>> # do sumthing that needs authentication > C>> } > C>> > C>> This will happily run in E_ALL &~ E_NOTICE whether $x == 'foo' or not. > C>> Attacker can then inject $secure in the query string, and it'll apply > C>> whether or not $x == 'foo'. This will be caught with error_reporting > C>> E_ALL. > > That's entirely different issue, having nothing to do with notices, but > with register_globals and mixing internal and user-supplied variables. The > fact that E_NOTICE may in some situation help you to find it is lucky (or, > on the second thought, unlucky - it may as well not happen, and you are > toast with all your belief in notices) coincidence, nothing more. > > C>> Yes, average PHP code is full of security or other holes. > > That's overbroad statement which is just wrong. I can show you a lot of > scripts generating a real lot of notices, but having no security hole. > > Also, note that fixing notice in the above code in the obvious way - > changing simple if() to isset and stuff - will shut up your precious > notice mechanism, while leaving the hole wide open. Is that what you want? > > -- > Stanislav Malyshev, Zend Products Engineer > stas@zend.com http://www.zend.com/ +972-3-6139665 ext.115 > > > > -- > PHP Quality Assurance Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-qa-unsubscribe@lists.php.net > For additional commands, e-mail: php-qa-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#63561) next »