Bug #74611 [NEW]: We use 'php://input', when we uploaded the binary file from html form.
| From: | aki dot sen dot 1209 at gmail dot com | Date: | Thu, 18 May 2017 14:32:42 +0000 |
| Subject: | Bug #74611 [NEW]: We use 'php://input', when we uploaded the binary file from html form. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209182@lists.php.net to get a copy of this message | ||
From: aki dot sen dot 1209 at gmail dot com
Operating system: Windows and LINUX
PHP version: 7.1.5
Package: *General Issues
Bug Type: Bug
Bug description:We use 'php://input', when we uploaded the binary file from html form.
Description:
------------
So when we uploaded binary file from html form, PHP usually cannot use
'php://input' right?
We usually use $_FILES, when we uploaded something binary.
But I discovered loophole it.
For example, you should set up '1024' with upload_max_filesize and
'1024' with post_max_size in php.ini.
Next you need to write 'ini_set("memory_limit", -1)' in source code
which you should execute.
So Let's upload something binary file to html form.
Then, You would notice what '$_FILES' and '$_POST' is empty.
But you can extract binary file from 'php://input'.
Let's use 'file_get_contents' for binary , to extract binary file from
raw 'php://input'.
You would watch the notice of warning from PHP on display, But You can
understand that the program was able to upload the binary file.
Test script:
---------------
<?php ini_set("memory_limit", -1);
print_r($_FILES);
print_r($_POST);
print("<br >");
ob_start();
print(file_get_contents("php://input"));
$get = ob_get_clean();
file_put_contents("/tmp/".time(), $get);
--
Edit bug report at https://bugs.php.net/bug.php?id=74611&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74611&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74611&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74611&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74611&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74611&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74611&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74611&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74611&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74611&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74611&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74611&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74611&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74611&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74611&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74611&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74611&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74611&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74611&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74611&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74611&r=mysqlcfg