Re: allow_url_fopen should be INI_ALL
| From: | Russell Nelson | Date: | Wed, 29 Jun 2005 06:13:14 +0000 |
| Subject: | Re: allow_url_fopen should be INI_ALL | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-16993@lists.php.net to get a copy of this message | ||
Gareth Ardron writes:
> You absolutely can't trust any input whatsoever and it must be
> validated.
Nope. Some functions are intrinsically safe, e.g. C's atol, or strtol.
It's all in the design, you see.
--
--My blog is at blog.russnelson.com | If you want to find
Crynwr sells support for free software | PGPok | injustice in economic
521 Pleasant Valley Rd. | +1 315-323-1241 | affairs, look for the
Potsdam, NY 13676-3213 | | hand of a legislator.