Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]
| From: | Matthew Leverton | Date: | Sun, 03 Sep 2000 17:17:53 +0000 |
| Subject: | Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload] | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15055@lists.php.net to get a copy of this message | ||
>My suggestion to all administrators of PHP enabled boxes is to change the
>register_globals in php.ini to off, and switch track_vars to on. This will
>however lead to most PHP scripts breaking. In the short term, disable any
>PHP scripts you have that provide file upload functionality until the
vendor
>of those scripts can provide a fix/determine non vulnerability.
Register globals is dangerous -- I always turn it off. One way to avoid this
potential security problem is to do explicitly say where a variable is
coming from:
$id = $HTTP_GET_VAR["id"];
The worst things are having system, session, and enivronment variables
being overridden by GET / POST vars. Obviously, you can switch the
order around in the config file, but in my opinion that's just skirting
around
the issue.
Another good thing to check for when a form is being submitted is the
referrer. If you can safely assume all users are on a modern browser,
you could disallow all form submissions that do not come from your
domain. Typically another site should never have to POSTdata to your
server.
In any case, there's a lot to be watching out for..
--
Matthew Leverton - matthew@aeroinc.net
----- Original Message -----
From: "Simon Edwards" <simon@animated.net.au>
To: <php-general@lists.php.net>
Sent: Sunday, September 03, 2000 11:21 PM
Subject: [PHP] [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file
upload]
>
> enjoy
>
> --
> Simon Edwards
>
> Animated Design, Melbourne
> http://www.animated.net.au/ Ph: (03) 98850990