Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]

From: Date: Sun, 03 Sep 2000 17:17:53 +0000
Subject: Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15055@lists.php.net to get a copy of this message
>My suggestion to all administrators of PHP enabled boxes is to change the >register_globals in php.ini to off, and switch track_vars to on. This will >however lead to most PHP scripts breaking. In the short term, disable any >PHP scripts you have that provide file upload functionality until the vendor >of those scripts can provide a fix/determine non vulnerability. Register globals is dangerous -- I always turn it off. One way to avoid this potential security problem is to do explicitly say where a variable is coming from: $id = $HTTP_GET_VAR["id"]; The worst things are having system, session, and enivronment variables being overridden by GET / POST vars. Obviously, you can switch the order around in the config file, but in my opinion that's just skirting around the issue. Another good thing to check for when a form is being submitted is the referrer. If you can safely assume all users are on a modern browser, you could disallow all form submissions that do not come from your domain. Typically another site should never have to POSTdata to your server. In any case, there's a lot to be watching out for.. -- Matthew Leverton - matthew@aeroinc.net ----- Original Message ----- From: "Simon Edwards" <simon@animated.net.au> To: <php-general@lists.php.net> Sent: Sunday, September 03, 2000 11:21 PM Subject: [PHP] [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload] > > enjoy > > -- > Simon Edwards > > Animated Design, Melbourne > http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15055) next »