Re: show_source() is easy to hack with.. SECURITY!!!
| From: | Simon Edwards | Date: | Fri, 01 Sep 2000 06:04:28 +0000 |
| Subject: | Re: show_source() is easy to hack with.. SECURITY!!! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-14729@lists.php.net to get a copy of this message | ||
Maxim Maletsky wrote:
> Hey, I just thought that if you are able to upload on someone's server a
> file, then include()ing in it
> You can actually broke&crack into many things on that server, unless
> show_source() is not protected or restricted...
show_source() is the least of your problems if you are allowing people
to upload files into a directory that is being served to the web. But
there is need that sometimes, like when you want to allow people to
upload images for a web based product catalogue for example, but you
want store the images on the filesystem not in the DB. In this situation
if someone uploads a php file instead of a jpeg the web server will just
execute it instead of servering it. That's bad. The way I do things now
is to place uploaded stuff into a directory by itself and to use an
apache .htaccess file to stop anything other than static content from
being served.
--------- .htaccess
# We basically disable all apache handlers here. Making sure
# that only static content is sent and that no php is executed.
SetHandler default-handler
-------
I crapped my daks when I first saw that security problem.
Also, in PHP3 for example. When you upload a file from
<input name=uploadfile type=file>
You get as form vars IRC (can't get to www.php.net right now):
uploadfile = OriginalName.jpg
uploadfile_name = /tmp/PHP5874593
Then you typically copy the tmp file etc. Is it possible to send bogus
form vars that look like this:
uploadfile = OriginalName.jpg
uploadfile_name = /etc/passwd
to trick the script into copying the password file into a dir that is
being served?
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990