Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:13275 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 1158 invoked by uid 1010); 12 Oct 2004 07:04:10 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 1109 invoked from network); 12 Oct 2004 07:04:09 -0000 Received: from unknown (HELO jdi.jdimedia.nl) (212.204.192.51) by pb1.pair.com with SMTP; 12 Oct 2004 07:04:09 -0000 Received: from localhost (localhost [127.0.0.1]) by jdi.jdimedia.nl (8.12.11/8.12.11) with ESMTP id i9C7481G019209 for ; Tue, 12 Oct 2004 09:04:08 +0200 Received: from localhost (localhost [127.0.0.1]) by jdi.jdimedia.nl (8.12.11/8.12.11) with ESMTP id i9C744OH019191; Tue, 12 Oct 2004 09:04:05 +0200 Date: Tue, 12 Oct 2004 09:04:04 +0200 (CEST) X-X-Sender: derick@localhost To: Sascha Schumann cc: Andi Gutmans , Christian Schneider , internals@lists.php.net In-Reply-To: Message-ID: References: <20041011100001.94254.qmail@pb1.pair.com> <20041011100001.94254.qmail@pb1.pair.com> <5.1.0.14.2.20041011152226.043e7ec0@localhost> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Virus-Scanned: by amavisd-new at jdimedia.nl Subject: Re: [PHP-DEV] HTTP Response Splitting From: derick@php.net (Derick Rethans) On Tue, 12 Oct 2004, Sascha Schumann wrote: > On Mon, 11 Oct 2004, Andi Gutmans wrote: > > > I think you are right. The only problem I can see is that people added more > > than one header with a header() call and it actually having worked under some > > SAPIs. My guess is that this has happened quite often and it might break quite > > a few apps. > > In contrast to other bad programming habbits, I have not seen > this in actual code anywhere so far. I did, can't remember where it was though. Derick -- Derick Rethans http://derickrethans.nl | http://ez.no | http://xdebug.org