Re: Hacker problem
| From: | CPT John W. Holmes | Date: | Wed, 12 Mar 2003 14:19:11 +0000 |
| Subject: | Re: Hacker problem | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-139306@lists.php.net to get a copy of this message | ||
Who cares where it comes from, just validate it. You can use POST and
HTTP_REFERRER (check spelling) to stop lazy people from messing with it if
that makes you feel better.
---John Holmes...
----- Original Message -----
From: <Sysadmin@saginawcontrol.com>
To: <Sysadmin@saginawcontrol.com>; <eurleif@buyer-brokerage.com>
Cc: <php-general@lists.php.net>
Sent: Wednesday, March 12, 2003 9:02 AM
Subject: RE: [PHP] Hacker problem
> So we aren't actually validating "where" the data is coming from, we
> are just validating the data?
>
> -----Original Message-----
> From: Leif K-Brooks [mailto:eurleif@buyer-brokerage.com]
> Sent: Wednesday, March 12, 2003 8:57 AM
> To: Sysadmin@saginawcontrol.com
> Cc: php-general@lists.php.net
> Subject: Re: [PHP] Hacker problem
>
>
> if(stristr($text,'badword') or stristr($text,'badword2') or
> strlen($text) > maxlength){
> die('Invalid!');
> }
>
> Sysadmin@saginawcontrol.com wrote:
>
>
> So how could you validate it server-side?
>
> -----Original Message-----
> From: Leif K-Brooks [ mailto:eurleif@buyer-brokerage.com]
> Sent: Wednesday, March 12, 2003 8:41 AM
> To: Sysadmin@saginawcontrol.com
> Cc: php-general@lists.php.net
> Subject: Re: [PHP] Hacker problem
>
>
> That's can still easily be spoofed. The only safe way is to validate
> the form server-side.
>
> Sysadmin@saginawcontrol.com wrote:
>
>
>
> Yes, theoretically...you could require it to be posted data. In order
> to do this you would have to make sure "registered_globals" is set to
> "off" in your php.ini and then for each variable posted from your form
> you will need to do something like this....
>
> $name=$_POST["name"];
>
> This will only post the variables if they have been "posted." Then
>
>
> you
>
>
> could use the referrer along with this and it will only allow data
>
>
> from
>
>
> that specific form. Hope this helps!
>
> Brian Drexler
>
> -----Original Message-----
> From: Pag [ mailto:dante@mail.telepac.pt]
> Sent: Wednesday, March 12, 2003 8:35 AM
> To: php-general@lists.php.net
> Subject: [PHP] Hacker problem
>
>
>
> Been having some hacker problems on my site, and a simple one:
>
> I have a shoutbox, a simple form with name and text that adds
> lines to the
> database. I do checks for insults, too long words, tags, etc, but its
> still
> possible to circumvent those checks by adding the data on the url
> instead
> of using the form. something like:
>
>
> www.domain.com/shoutb.php?name=hacker&text=generalnonsenseandbadwords
>
> To prevent this, i tried tracing the http_referral so that only
> data from
> inside the site goes into the shoutbox. THe problem is that if you do
> that
> url above after visiting my site, the http_referral obviously thinks
> its
> coming from inside the site. :-P
> How can i solve this? Is there any way to prevent data adding
>
>
> from
>
>
> outside? Maybe some invisible check on the form or something?
>
> Thanks.
>
> Pag
>
>
>
>
>
>
>
>
>
>
>
> --
> The above message is encrypted with double rot13 encoding. Any
> unauthorized attempt to decrypt it will be prosecuted to the full
> extent of the law.
>
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>