#44366 [Opn->Bgs]: Regex bypass using POISON NULL BYTE

From: Date: Sat, 08 Mar 2008 11:47:27 +0000
Subject: #44366 [Opn->Bgs]: Regex bypass using POISON NULL BYTE
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-123053@lists.php.net to get a copy of this message
ID: 44366 Updated by: johannes@php.net Reported By: charlesfol at hotmail dot fr -Status: Open +Status: Bogus Bug Type: *Regular Expressions Operating System: nux/win PHP Version: 5.2.5 New Comment: As the reporter said ;-) Previous Comments: ------------------------------------------------------------------------ [2008-03-08 11:02:32] charlesfol at hotmail dot fr OK, in fact I found that this was a known problem. I apologize about your wasted time =) ------------------------------------------------------------------------ [2008-03-08 03:12:53] charlesfol at hotmail dot fr Description: ------------ I discovered that in this PHP version, regex could be bypassed using \0 (%00) a.k.a. POISON NULL BYTE. Reproduce code: --------------- <?php $var=$_GET['var']; $is_alphanum_var = ereg("^[a-zA-Z0-9]+$",$var); print "$is_alphanum_var\n$var"; ?> Expected result: ---------------- Normally if code contains ad chars such as %,", or _ it will be detected by the regex. Actual result: -------------- But if we use this URL: http://site.com/page.php?var=test%00_- $is_alphanum_var RETURNS 1, BUT $var CONTAINS _- Security HOLE. Warmly, Charles "real" FOL. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=44366&edit=1

« previous php.bugs (#123053) next »