Re: show_source() is easy to hack with.. SECURITY!!!

From: Date: Fri, 01 Sep 2000 06:04:28 +0000
Subject: Re: show_source() is easy to hack with.. SECURITY!!!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-14729@lists.php.net to get a copy of this message
Maxim Maletsky wrote: > Hey, I just thought that if you are able to upload on someone's server a > file, then include()ing in it > You can actually broke&crack into many things on that server, unless > show_source() is not protected or restricted... show_source() is the least of your problems if you are allowing people to upload files into a directory that is being served to the web. But there is need that sometimes, like when you want to allow people to upload images for a web based product catalogue for example, but you want store the images on the filesystem not in the DB. In this situation if someone uploads a php file instead of a jpeg the web server will just execute it instead of servering it. That's bad. The way I do things now is to place uploaded stuff into a directory by itself and to use an apache .htaccess file to stop anything other than static content from being served. --------- .htaccess # We basically disable all apache handlers here. Making sure # that only static content is sent and that no php is executed. SetHandler default-handler ------- I crapped my daks when I first saw that security problem. Also, in PHP3 for example. When you upload a file from <input name=uploadfile type=file> You get as form vars IRC (can't get to www.php.net right now): uploadfile = OriginalName.jpg uploadfile_name = /tmp/PHP5874593 Then you typically copy the tmp file etc. Is it possible to send bogus form vars that look like this: uploadfile = OriginalName.jpg uploadfile_name = /etc/passwd to trick the script into copying the password file into a dir that is being served? -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#14729) next »