#18727 [Bgs]: XSS in I/O Function Output

From: Date: Sat, 03 Aug 2002 20:22:37 +0000
Subject: #18727 [Bgs]: XSS in I/O Function Output
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-15937@lists.php.net to get a copy of this message
ID: 18727 User updated by: mattmurphy@kc.rr.com Reported By: mattmurphy@kc.rr.com Status: Bogus Bug Type: Output Control Operating System: Win32 PHP Version: 4.2.2 New Comment: Now, you tell me how a programmer could prevent this attack. If he HTML-encoded his file name before using it, it would screw up his script's function. The problem is *not* in the script, but in PHP's fopen() function. A simple HTML encode (e.g, instead of "<SCRIPT>", "&lt;SCRIPT&gt;") would do the job of avoiding the bug, AND would not change the appearence of the output. The current situation is at best unsafe. Previous Comments: ------------------------------------------------------------------------ [2002-08-03 16:17:19] cynic@php.net it's the programmer's responsibility to prevent such attacks. i for one surely wouldn't want php muck with the error output while writing some quick scripts. in larger applications, you need custom error handler and/or display_errors = off anyway. so what's the deal? ------------------------------------------------------------------------ [2002-08-03 16:11:01] mattmurphy@kc.rr.com Once again, I'm astounded by the overwhelmingly negative message that the PHP Group sends users of PHP sites -- thanks to us, somebody can steal your personal information! Oh, and, thanks for your business. That is at least counter-productive, yes? ------------------------------------------------------------------------ [2002-08-03 16:00:54] sander@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php ------------------------------------------------------------------------ [2002-08-03 15:40:37] mattmurphy@kc.rr.com This applies to any PHP script that opens files based on some kind of user-input inserted into the file name. If the file open fails, PHP returns a warning. In that warning is the file name that was input. If the user-input were to contain a specially crafted piece of data, arbitrary code could be executed: <?php $handle = fopen("C:\\INETPUB\\WWWROOT\\" . $_GET["resource"], "rb"); ?> http://localhost/fopen.php?resource={SCRIPT}alert('xss'){/SCRIPT} Replace "{" with "<" and "}" with ">" and you are ready to go. When you hit the enter key, the browser urlencodes the malicious string, and PHP attempts to open the file, resulting in the vulnerability. Solution fopen() should *not* return the file name in raw form to the browser. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18727&edit=1

« previous php.bugs (#15937) next »