Re: Re: [Fwd: (SRADV00001) Arbitraryfiledisclosurethrough PHP file upload]
| From: | Simon Edwards | Date: | Tue, 05 Sep 2000 00:59:44 +0000 |
| Subject: | Re: Re: [Fwd: (SRADV00001) Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15192@lists.php.net to get a copy of this message | ||
Ron Chmara wrote:
> Would this work for most users, without having to patch, to make sure
> they are operating on a user uploaded file?
> <?
> $validtmpdir = get_cfg_var("upload_tmp_dir");
> /* make sure you're using an uploaded file */
> if (strstr ("$validtmpdir", "$userfile") != 0){
> copy ("$userfile" "/place/to/put/uploaded/file");
> .....
> } else {
> echo "Not an uploaded file!";
> exit;
> }
> ?>
No, because if $validtmpdir = "/usr/tmp/" and
$userfile="/usr/tmp/../../etc/passwd" your code will accept it. The only
solution is to take the file part of $userfile and append it to
$validtmpdir before attempting a copy. This should ensure that you are
in the right directory.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990