RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!
| From: | UGBI) | Date: | Mon, 11 Feb 2002 14:46:27 +0000 |
| Subject: | RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!! | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-84278@lists.php.net to get a copy of this message | ||
I think you all are missing the point that *R&zE is making.
The software you use/create should be bugfree and free from undocumented
features. Otherwise security risks could occur. And ofcourse all other
safe-guard (like checking input, correct rights on the FileSystem) should be
placed too.
It is bugs like these who create life for Hackers and viruses (like nimda).
Of course you can say that is the users own fault. But it is the developers
duty to inform and advise users, and not to look the other way in the hope
that it goes away.
Jerry
> -----Original Message-----
> From: Andrew Hill [mailto:ahill@openlinksw.com]
> Sent: Monday, February 11, 2002 3:34 PM
> To: * R&zE:; Lars Torben Wilson
> Cc: PHP General Mailinglist
> Subject: RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!
>
>
> > I understand you try to 'protect' your own product, but you have to
> > stay a bit realistic about some things. Ofcourse I check the input.
> > But you know... there's absolutely nothing wrong with allowing
> > quotes to be stored in the database. It's just that awful 'feature'
> > that makes it rather dangerous to do. If that feature/bug was
> > documented _anywhere_ it would still not be good, but at least
> > someone would know that PHP does this. But no... it's not
> > documented, not anywhere! You can't check user input on stuff you
> > don't know it can harm anything. Like I said... quotes are very
> > normal to be allowed in the database.
> >
> > It would be a good thing if you guys do something of:
> >
> > 1. Good rid of the bug(/feature) right a way or
> > 2. Document it clearly. Eg. in the documentation of odbc_execute().
> >
>
> I'll echo Lars that you should always validate data, whether
> or not you
> assume it to be safe.
> That being said, if '/etc/passwd' is readable by your
> webserver you've got
> bigger problems.
>
> Best regards,
> Andrew Hill
> Director of Technology Evangelism
> http://www.openlinksw.com/virtuoso/whatis.htm
> OpenLink Virtuoso Internet Data Integration Server
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
The information contained in this email is confidential and
may be legally privileged. It is intended solely for the
addressee. Access to this email by anyone else is
unauthorized. If you are not the intended recipient, any
form of disclosure, production, distribution or any action
taken or refrained from in reliance on it, is prohibited and
may be unlawful. Please notify the sender immediately.
The content of the email is not legally binding unless
confirmed by letter bearing two authorized signatures.