RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!

From: Date: Mon, 11 Feb 2002 14:46:27 +0000
Subject: RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!
Groups: php.general 
Request: Send a blank email to php-general+get-84278@lists.php.net to get a copy of this message
I think you all are missing the point that *R&zE is making. The software you use/create should be bugfree and free from undocumented features. Otherwise security risks could occur. And ofcourse all other safe-guard (like checking input, correct rights on the FileSystem) should be placed too. It is bugs like these who create life for Hackers and viruses (like nimda). Of course you can say that is the users own fault. But it is the developers duty to inform and advise users, and not to look the other way in the hope that it goes away. Jerry > -----Original Message----- > From: Andrew Hill [mailto:ahill@openlinksw.com] > Sent: Monday, February 11, 2002 3:34 PM > To: * R&zE:; Lars Torben Wilson > Cc: PHP General Mailinglist > Subject: RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!! > > > > I understand you try to 'protect' your own product, but you have to > > stay a bit realistic about some things. Ofcourse I check the input. > > But you know... there's absolutely nothing wrong with allowing > > quotes to be stored in the database. It's just that awful 'feature' > > that makes it rather dangerous to do. If that feature/bug was > > documented _anywhere_ it would still not be good, but at least > > someone would know that PHP does this. But no... it's not > > documented, not anywhere! You can't check user input on stuff you > > don't know it can harm anything. Like I said... quotes are very > > normal to be allowed in the database. > > > > It would be a good thing if you guys do something of: > > > > 1. Good rid of the bug(/feature) right a way or > > 2. Document it clearly. Eg. in the documentation of odbc_execute(). > > > > I'll echo Lars that you should always validate data, whether > or not you > assume it to be safe. > That being said, if '/etc/passwd' is readable by your > webserver you've got > bigger problems. > > Best regards, > Andrew Hill > Director of Technology Evangelism > http://www.openlinksw.com/virtuoso/whatis.htm > OpenLink Virtuoso Internet Data Integration Server > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > The information contained in this email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this email by anyone else is unauthorized. If you are not the intended recipient, any form of disclosure, production, distribution or any action taken or refrained from in reliance on it, is prohibited and may be unlawful. Please notify the sender immediately. The content of the email is not legally binding unless confirmed by letter bearing two authorized signatures.

« previous php.general (#84278) next »