Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]
| From: | Rasmus Lerdorf | Date: | Mon, 04 Sep 2000 05:20:36 +0000 |
| Subject: | Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload] | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15056@lists.php.net to get a copy of this message | ||
> >My suggestion to all administrators of PHP enabled boxes is to change the
> >register_globals in php.ini to off, and switch track_vars to on. This will
> >however lead to most PHP scripts breaking. In the short term, disable any
> >PHP scripts you have that provide file upload functionality until the
> vendor
> >of those scripts can provide a fix/determine non vulnerability.
>
> Register globals is dangerous -- I always turn it off. One way to avoid this
> potential security problem is to do explicitly say where a variable is
> coming from:
>
> $id = $HTTP_GET_VAR["id"];
>
> The worst things are having system, session, and enivronment variables
> being overridden by GET / POST vars. Obviously, you can switch the
> order around in the config file, but in my opinion that's just skirting
> around the issue.
But this does nothing in this case since the issue is that POST variables
in the same form are overwriting other POST variables. Turning off
register_globals has nothing to do with this issue and the alert is wrong
on this point.
-Rasmus