Re: PHP 5.1
| From: | Christian Schneider | Date: | Wed, 02 Feb 2005 00:17:33 +0000 |
| Subject: | Re: PHP 5.1 | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-14488@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf wrote:
I don't actually see it as a per-script thing. Obviously the ini would be per-dir Apache configurable, but I see this as being something set across the board on a dedicated server that defines the security policy of that server. Shared servers are most likely not going to be able toUh, that's a big goal but also asking for trouble. As you pointed out there is a different rule on what's safe for a specific input variable based on what it's used for (e.g. SQL, output, shell arg) and what's not. Wouldn't one have to set up default filters for every possible use to be safe then, i.e. a combination of all filters? Another major point would be to handle UTF8 properly, something which is not easily handled by regular expressions, right? - Chris