RE: [PHP-DEV] Re: #19286 [NEW]: header() Control Char Injection
| From: | James Cox | Date: | Sun, 08 Sep 2002 03:10:47 +0000 |
| Subject: | RE: [PHP-DEV] Re: #19286 [NEW]: header() Control Char Injection | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-88059@lists.php.net to get a copy of this message | ||
> Yasuo Ohgaki wrote:
> > This obvious security risk is mentioned in bugtraq today.
> >
> > IMHO, this is users' fault. They must check values before
> > using it. In this specfic case, user should use simple regex
> > before feeding str to header().
> >
> > Any opinion to meke this to "won't fix"?
>
> One thing we could do is force header parameter a single line.
> Any idea it may broke applications?
>
Don't do that.
(seriously, the thing i'm working on right now relies on abusing the http
protocol... this is one way i'm doing it...)