Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:71278 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 57595 invoked from network); 19 Jan 2014 20:57:07 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 19 Jan 2014 20:57:07 -0000 Authentication-Results: pb1.pair.com smtp.mail=lester@lsces.co.uk; spf=permerror; sender-id=unknown Authentication-Results: pb1.pair.com header.from=lester@lsces.co.uk; sender-id=unknown Received-SPF: error (pb1.pair.com: domain lsces.co.uk from 217.147.176.204 cause and error) X-PHP-List-Original-Sender: lester@lsces.co.uk X-Host-Fingerprint: 217.147.176.204 mail4.serversure.net Linux 2.6 Received: from [217.147.176.204] ([217.147.176.204:38469] helo=mail4.serversure.net) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 8D/AF-61840-12C3CD25 for ; Sun, 19 Jan 2014 15:57:06 -0500 Received: (qmail 25666 invoked by uid 89); 19 Jan 2014 20:57:02 -0000 Received: by simscan 1.3.1 ppid: 25658, pid: 25662, t: 0.0700s scanners: attach: 1.3.1 clamav: 0.96/m:52 Received: from unknown (HELO linux-dev4.lsces.org.uk) (lester@rainbowdigitalmedia.org.uk@81.138.11.136) by mail4.serversure.net with ESMTPA; 19 Jan 2014 20:57:02 -0000 Message-ID: <52DC3CB4.5090503@lsces.co.uk> Date: Sun, 19 Jan 2014 20:59:32 +0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:26.0) Gecko/20100101 Firefox/26.0 SeaMonkey/2.23 MIME-Version: 1.0 To: PHP internals References: <1390082096.14862.72482025.5D36E64F@webmail.messagingengine.com> <52DB2E4D.8000009@sugarcrm.com> <1390096353.18659.72527933.474C16A5@webmail.messagingengine.com> <52DB310A.9040506@sugarcrm.com> <1390099947.26938.72538325.1FDD1F20@webmail.messagingengine.com> <52DBA5B2.20304@lsces.co.uk> <1390154806.5657.72705681.06A9F994@webmail.messagingengine.com> In-Reply-To: <1390154806.5657.72705681.06A9F994@webmail.messagingengine.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [PHP-DEV] Bug 62479 From: lester@lsces.co.uk (Lester Caine) Will Fitch wrote: > On Sun, Jan 19, 2014, at 02:15 AM, Lester Caine wrote: >> >Will Fitch wrote: >>> > >Then again, I didn't expect to have >>> > >a bug where single quotes are part of the password, so there's always a >>> > >surprise. >> > >> >Leaving holes that can possibly be used by hackers is the problem here. >> >IF >> >someone finds an edge case that does not get handled their next step is >> >to see >> >if it can be exploited? Code review is not a matter of 'surprise' but >> >rather >> >'what have I missed that could be a problem'? > I agree. However, this is more of a situation of not accounting for all > situations as opposed to introducing a security flaw. As I told Stas, > I'm going to update to account for beginning/ending quotes. Many of the edge cases that get missed are quite benign but some of them can be a surprise. It is perhaps a little surprising how some holes can be exploited, even when we thought they were safe :( -- Lester Caine - G8HFL ----------------------------- Contact - http://lsces.co.uk/wiki/?page=contact L.S.Caine Electronic Services - http://lsces.co.uk EnquirySolve - http://enquirysolve.com/ Model Engineers Digital Workshop - http://medw.co.uk Rainbow Digital Media - http://rainbowdigitalmedia.co.uk