show_source() is easy to hack with.. SECURITY!!!

From: Date: Fri, 01 Sep 2000 05:43:03 +0000
Subject: show_source() is easy to hack with.. SECURITY!!!
Groups: php.general 
Request: Send a blank email to php-general+get-14727@lists.php.net to get a copy of this message
Hey, I just thought that if you are able to upload on someone's server a file, then include()ing in it echo ' <form action="'.$PHP_SELF.'"> <input type="text" size="20" name="source" value="'.$source.'"> </form> <P><PRE>'; if ($source) show_source (substr($DOCUMENT_ROOT, 0, 17).$source); //if you sure that the full path is /home/httpd/html/ //and you know how they create accounts... echo '</PRE>'; You can actually broke&crack into many things on that server, unless show_source() is not protected or restricted... Is that possible to disallow this function somehow? php.ini? Maxim Maletsky - maxim@j-door.com <mailto:maxim@j-door.com> Webmaster, J-Door.com / J@pan Inc. LINC Media, Inc. TEL: 03-3499-2175 x 1271 FAX: 03-3499-3109 http://www.j-door.com <http://www.j-door.com/> http://www.japaninc.net <http://www.japaninc.net/> http://www.lincmedia.co.jp <http://www.lincmedia.co.jp/>

« previous php.general (#14727) next »