Re: potential solution to user streams + allow_url_include=off

From: Date: Sat, 19 May 2007 07:32:38 +0000
Subject: Re: potential solution to user streams + allow_url_include=off
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-29536@lists.php.net to get a copy of this message
At the moment they are very predictable. You send them a security bug and first they try to tell you that you are totally wrong (because you made a
I wonder if you actually aware of the fact that there's no such single entity as "PHP developers" and each of them is entirely different living human? And these humans sometimes are in disagreement and some of them are wrong? And then the thing called "discussion" happens and it's not always about conspiring against certain security researchers? There's no "them". Try to think about it for a minute.
They will do something else to prove that they "outsmarted" you. Yeah
I wonder also if you are aware of the fact that not everybody is concerned with the question of who outsmarts whom here but some actually more concerned about fixing actual problems?
guess what their fix is of course not a solution and as usual fixes just one of the symptoms.
If you are aware of some security problems in current PHP sources you are as always welcome to report them and they will be fixed. I think everybody here as always are thankful for any help we can get. -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/

« previous php.internals (#29536) next »