Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]

From: Date: Mon, 04 Sep 2000 05:20:36 +0000
Subject: Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15056@lists.php.net to get a copy of this message
> >My suggestion to all administrators of PHP enabled boxes is to change the > >register_globals in php.ini to off, and switch track_vars to on. This will > >however lead to most PHP scripts breaking. In the short term, disable any > >PHP scripts you have that provide file upload functionality until the > vendor > >of those scripts can provide a fix/determine non vulnerability. > > Register globals is dangerous -- I always turn it off. One way to avoid this > potential security problem is to do explicitly say where a variable is > coming from: > > $id = $HTTP_GET_VAR["id"]; > > The worst things are having system, session, and enivronment variables > being overridden by GET / POST vars. Obviously, you can switch the > order around in the config file, but in my opinion that's just skirting > around the issue. But this does nothing in this case since the issue is that POST variables in the same form are overwriting other POST variables. Turning off register_globals has nothing to do with this issue and the alert is wrong on this point. -Rasmus

« previous php.general (#15056) next »