Bug->Doc #74611 [Opn->Ver]: php://input is available for multipart/form-data when post_max_size error

From: Date: Thu, 18 May 2017 15:06:10 +0000
Subject: Bug->Doc #74611 [Opn->Ver]: php://input is available for multipart/form-data when post_max_size error
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14702@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74611&edit=1 ID: 74611 Updated by: requinix@php.net Reported by: aki dot sen dot 1209 at gmail dot com -Summary: We use 'php://input', when we uploaded the binary file from html form. +Summary: php://input is available for multipart/form-data when post_max_size error -Status: Open +Status: Verified -Type: Bug +Type: Documentation Problem Package: *General Issues Operating System: Windows and LINUX PHP Version: 7.1.5 Block user comment: N Private report: N New Comment: PHP will read the request body (php://input) for multipart/form-data requests, which means it is not then available to read in userland. However PHP checks the Content-Length header first; if the value exceeds post_max_size then it will not read the body at all, thus making it available via php://input after all. The docs for php://input http://php.net/manual/en/wrappers.php.php#wrappers.php.input say simply that it is not available for multipart/form-data - I think this interesting edge case is worth mentioning, even if there's not much practical usage for it. However I'd keep it brief there and instead say more in the file uploads area. http://php.net/manual/en/features.file-upload.php Previous Comments: ------------------------------------------------------------------------ [2017-05-18 14:32:39] aki dot sen dot 1209 at gmail dot com Description: ------------ So when we uploaded binary file from html form, PHP usually cannot use 'php://input' right? We usually use $_FILES, when we uploaded something binary. But I discovered loophole it. For example, you should set up '1024' with upload_max_filesize and '1024' with post_max_size in php.ini. Next you need to write 'ini_set("memory_limit", -1)' in source code which you should execute. So Let's upload something binary file to html form. Then, You would notice what '$_FILES' and '$_POST' is empty. But you can extract binary file from 'php://input'. Let's use 'file_get_contents' for binary , to extract binary file from raw 'php://input'. You would watch the notice of warning from PHP on display, But You can understand that the program was able to upload the binary file. Test script: --------------- <?php ini_set("memory_limit", -1); print_r($_FILES); print_r($_POST); print("<br >"); ob_start(); print(file_get_contents("php://input")); $get = ob_get_clean(); file_put_contents("/tmp/".time(), $get); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74611&edit=1

« previous php.doc.bugs (#14702) next »