Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
| From: | Lars Torben Wilson | Date: | Tue, 05 Sep 2000 23:21:28 +0000 |
| Subject: | Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 2 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-general+get-15401@lists.php.net to get a copy of this message | ||
Stanislav Malyshev writes:
> LTW>> <?php
> LTW>> $safepath = get_cfg_var('upload_tmp_dir') . '/' .
> LTW>> basename($userfile);
> LTW>>
> LTW>> /* etc...*/
> LTW>> ?>
>
> That's closer to the point. Now why won't PHP really do it?
>
> --
> Stanislav Malyshev stas@zend.com http://www.zend.com/
>
> +972-3-6139665 ext.106
Do you mean 'do it' as in why doesn't PHP handle this so the user
doesn't have to? I dunno. I believe perhaps it should--at least to the
point of doing some simple checks to ensure that the file lives in the
upload directory and matches the location which PHP comes up with for
the temp files and perhaps issuing a warning if needed.
Or, if you mean 'do it' as in why won't the example above work in some
cases, thanks for the heads up. :) In the default php.ini,
upload_tmp_dir is undefined and get_cfg_var('upload_tmp_dir') returns
nothing, as does ini_get('upload_tmp_dir'). I think a safer fix (for
the time being) would be:
$uploadpath = dirname(tempnam('', '')) . '/' . basename($userfile);
Note that this depends on the fact that PHP uses tempnam() to name the
temporary file; this (I suppose) may change in the future, but for now
it's useful.
Can someone check this to see whether it addresses the problem more
aptly than what Ron and I came up with earlier?
<?php
error_reporting(E_ALL);
/* Check for an attack on file uploads.
* Dependent upon current internal PHP functionality.
* Meant only as a stopgap 'til something better comes along.
* I think you'll need to change the slashes for Windows. */
function fix_upload_path($filename) {
if (!$tmp_prefix = ini_get('upload_tmp_dir')) {
$tmp_prefix = dirname(tempnam('', ''));
}
return ereg_replace('/+', '/', "$tmp_prefix/" .
basename($filename));
}
if (!empty($userfile)) {
echo "\$userfile: '$userfile'\n";
// Make sure file is coming from upload directory
$uploadpath = fix_upload_path($userfile);
if ($userfile != $uploadpath) {
echo "<b>Possible upload attack.</b>\n";
} else {
echo "<b>Safe; displaying:</b>\n";
echo
cat $uploadpath;
}
echo "\$uploadpath: '$uploadpath'\n";
}
?>
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+