#18727 [Bgs]: XSS in I/O Function Output
| From: | cynic@php.net | Date: | Sat, 03 Aug 2002 20:30:38 +0000 |
| Subject: | #18727 [Bgs]: XSS in I/O Function Output | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15942@lists.php.net to get a copy of this message | ||
ID: 18727
Updated by: cynic@php.net
Reported By: mattmurphy@kc.rr.com
Status: Bogus
Bug Type: Output Control
Operating System: Win32
PHP Version: 4.2.2
New Comment:
yup. the fact that php doesn't hold programmers by the hand doesn't
necessarily mean it's broken.
Previous Comments:
------------------------------------------------------------------------
[2002-08-03 16:29:23] cynic@php.net
i said "custom error handler and/or display_errors = off"
please, leave this pr in the bogus state.
------------------------------------------------------------------------
[2002-08-03 16:28:56] eru@php.net
You could prevent this attack by verifying the input with file_exists
or something similar. You should always parse userinput through some
sanity-check, before you process it, and this is within the
responsibility of the programmer, not of PHP.
------------------------------------------------------------------------
[2002-08-03 16:27:27] msopacua@idg.nl
So, this 'security issue' occurs when:
1) Errors are spit to the browser instead of a log, like it is, before
you put it in production, right?
2) fopen is called, on a non-existing file (see: file_exists), directly
accepting user input - ahum.
Additionally - the 'vulnerability' has got nothing to do with PHP, but
everything with browsers and JavaScript.
------------------------------------------------------------------------
[2002-08-03 16:23:31] mattmurphy@kc.rr.com
Didn't change the status... :-)
------------------------------------------------------------------------
[2002-08-03 16:22:36] mattmurphy@kc.rr.com
Now, you tell me how a programmer could prevent this attack. If he
HTML-encoded his file name before using it, it would screw up his
script's function. The problem is *not* in the script, but in PHP's
fopen() function.
A simple HTML encode (e.g, instead of "<SCRIPT>",
"<SCRIPT>")
would do the job of avoiding the bug, AND would not change the
appearence of the output. The current situation is at best unsafe.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/18727
--
Edit this bug report at http://bugs.php.net/?id=18727&edit=1