Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
| From: | Andreas Pour | Date: | Tue, 05 Sep 2000 02:36:21 +0000 |
| Subject: | Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 2 3 4 5 6 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-dev+get-32058@lists.php.net to get a copy of this message | ||
Lars Torben Wilson wrote:
>
> Ron Chmara writes:
> > Oh, thats an easy one. :-)
> > <?
> > $validtmpdir = get_cfg_var("upload_tmp_dir");
> > // get the path
> >
> > $uploaded_path_array = spilt("/","$userfile");
> > //split the upload name into its components
> >
> > $inverted_path = array_reverse ($uploaded_path_array);
> > // reverse the array, so any ending pathname will now be first
> >
> > $accurate_pathname = "$validtmpdir" . "$inverted_path[0]";
> >
> > if (file_exists($accurate_pathname )){
> > //still look for proper temp name
> > copy ("$accurate_pathname", "/place/to/put/uploaded/file");
> > } else {
> > echo "Not an uploaded file!";
> > exit;
> > }
> > ?>
>
> I think you can reduce the first few operations to one line to skip
> the array processing (untested):
>
> <?php
> $safepath = get_cfg_var('upload_tmp_dir') . '/' . basename($userfile);
Hi,
You can also add a little (untested) embellishment such as:
if ($userfile != basename($userfile))
{
mail($WEBMASTER, "UserFile Attack Detected", "IP Address =
'$REMOTE_ADDR'\nUser id = ....");
echo "Foiled again<BR>";
}
else
{
process the data
}
Ciao,
Andreas