Bug #76671 [Com]: bypass strpos verification

From: Date: Mon, 28 Jan 2019 05:41:55 +0000
Subject: Bug #76671 [Com]: bypass strpos verification
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219236@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76671&edit=1 ID: 76671 Comment by: aa963577242 at gmail dot com Reported by: guilhermeassmannn at gmail dot com Summary: bypass strpos verification Status: Not a bug Type: Bug Package: Strings related Operating System: MacOS High Sierra & Ubuntu 16.04 PHP Version: Irrelevant Block user comment: N Private report: N New Comment: ok,,,,,,,i am sorry, i think this is not strpos function bug,but this is another bug...... Previous Comments: ------------------------------------------------------------------------ [2019-01-28 05:29:16] aa963577242 at gmail dot com who say this is not bug. i just say you don't know web security.-_- ------------------------------------------------------------------------ [2018-07-27 11:29:26] rasmus@php.net Of course not, but strpos() can't possibly know what sort of context your string is going to be used in. Only you know it is a URL. In this particular case you could simply check for '%' and urldecode() until they are gone. eg. while(strstr($url,'%')) $url = urldecode($url); ------------------------------------------------------------------------ [2018-07-27 10:24:21] a at b dot c dot de Well, you shouldn't be trying to prevent attacks by second-guessing what an attacker might do. Instead of *forbidding* certain requests, only *allow* requests that you know are safe. ------------------------------------------------------------------------ [2018-07-27 02:56:17] guilhermeassmannn at gmail dot com ok but, using urldecode() we can do with triple encode,so the correct would be to never use the strpos for the user? ------------------------------------------------------------------------ [2018-07-27 02:00:48] rasmus@php.net strpos() is a low-level string manipulation function. If the string you are parsing has a higher-level meaning, you need to handle that yourself before calling strpos(). That might mean calling urldecode() if you know the string is an encoded url. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76671 -- Edit this bug report at https://bugs.php.net/bug.php?id=76671&edit=1

« previous php.bugs (#219236) next »