Bug #76671 [Com]: bypass strpos verification
| From: | aa963577242 at gmail dot com | Date: | Mon, 28 Jan 2019 05:41:55 +0000 |
| Subject: | Bug #76671 [Com]: bypass strpos verification | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-219236@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76671&edit=1
ID: 76671
Comment by: aa963577242 at gmail dot com
Reported by: guilhermeassmannn at gmail dot com
Summary: bypass strpos verification
Status: Not a bug
Type: Bug
Package: Strings related
Operating System: MacOS High Sierra & Ubuntu 16.04
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
ok,,,,,,,i am sorry, i think this is not strpos function bug,but this is another bug......
Previous Comments:
------------------------------------------------------------------------
[2019-01-28 05:29:16] aa963577242 at gmail dot com
who say this is not bug. i just say you don't know web security.-_-
------------------------------------------------------------------------
[2018-07-27 11:29:26] rasmus@php.net
Of course not, but strpos() can't possibly know what sort of context your string is going to be
used in. Only you know it is a URL. In this particular case you could simply check for '%'
and urldecode() until they are gone.
eg. while(strstr($url,'%')) $url = urldecode($url);
------------------------------------------------------------------------
[2018-07-27 10:24:21] a at b dot c dot de
Well, you shouldn't be trying to prevent attacks by second-guessing what an attacker might do.
Instead of *forbidding* certain requests, only *allow* requests that you know are safe.
------------------------------------------------------------------------
[2018-07-27 02:56:17] guilhermeassmannn at gmail dot com
ok but, using urldecode() we can do with triple encode,so the correct would be to never use the
strpos for the user?
------------------------------------------------------------------------
[2018-07-27 02:00:48] rasmus@php.net
strpos() is a low-level string manipulation function. If the string you are parsing has a
higher-level meaning, you need to handle that yourself before calling strpos(). That might mean
calling urldecode() if you know the string is an encoded url.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76671
--
Edit this bug report at https://bugs.php.net/bug.php?id=76671&edit=1