Bug #2472: poison null byte
| From: | kerb at fnusa dot com | Date: | Sat, 09 Oct 1999 12:31:02 +0000 |
| Subject: | Bug #2472: poison null byte | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11639@lists.php.net to get a copy of this message | ||
From: kerb@fnusa.com
Operating system: Linux 2.2.12
PHP version: 3.0.12
PHP Bug Type: Other
Bug description: poison null byte
I'm not sure if you've been notified of this, but the same problem that exists in
perl-based CGI scripts
involving the "poison null byte" exists in PHP. I was able to POST the following to a
script:
name=John%00+Q.+Public
which should translate to "John Q. Public", although if you post that to a PHP document
such as
<?php
echo "Your name is $name";
?>
it will actually print "Your name is John" and stop there. in perl, I know I can
s/%00//ge my URL-encoded strings before I actually decode them, but PHP (from the bit I have used
it) decodes all posted variables automatically. For more detail into the inner working of the
poison null byte, read Phrack issue 55, article 7: http://www.phrack.com/search.phtml?view&article=p55-7
-Kerb