Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 23:21:28 +0000
Subject: Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
References: 1 2  Groups: php.dev php.general 
Request: Send a blank email to php-general+get-15401@lists.php.net to get a copy of this message
Stanislav Malyshev writes: > LTW>> <?php > LTW>> $safepath = get_cfg_var('upload_tmp_dir') . '/' . > LTW>> basename($userfile); > LTW>> > LTW>> /* etc...*/ > LTW>> ?> > > That's closer to the point. Now why won't PHP really do it? > > -- > Stanislav Malyshev stas@zend.com http://www.zend.com/ > > +972-3-6139665 ext.106 Do you mean 'do it' as in why doesn't PHP handle this so the user doesn't have to? I dunno. I believe perhaps it should--at least to the point of doing some simple checks to ensure that the file lives in the upload directory and matches the location which PHP comes up with for the temp files and perhaps issuing a warning if needed. Or, if you mean 'do it' as in why won't the example above work in some cases, thanks for the heads up. :) In the default php.ini, upload_tmp_dir is undefined and get_cfg_var('upload_tmp_dir') returns nothing, as does ini_get('upload_tmp_dir'). I think a safer fix (for the time being) would be: $uploadpath = dirname(tempnam('', '')) . '/' . basename($userfile); Note that this depends on the fact that PHP uses tempnam() to name the temporary file; this (I suppose) may change in the future, but for now it's useful. Can someone check this to see whether it addresses the problem more aptly than what Ron and I came up with earlier? <?php error_reporting(E_ALL); /* Check for an attack on file uploads. * Dependent upon current internal PHP functionality. * Meant only as a stopgap 'til something better comes along. * I think you'll need to change the slashes for Windows. */ function fix_upload_path($filename) { if (!$tmp_prefix = ini_get('upload_tmp_dir')) { $tmp_prefix = dirname(tempnam('', '')); } return ereg_replace('/+', '/', "$tmp_prefix/" . basename($filename)); } if (!empty($userfile)) { echo "\$userfile: '$userfile'\n"; // Make sure file is coming from upload directory $uploadpath = fix_upload_path($userfile); if ($userfile != $uploadpath) { echo "<b>Possible upload attack.</b>\n"; } else { echo "<b>Safe; displaying:</b>\n"; echo cat $uploadpath; } echo "\$uploadpath: '$uploadpath'\n"; } ?> -- +----------------------------------------------------------------+ |Torben Wilson <torben@php.net> Netmill iTech| |http://www.coastnet.com/~torben http://www.netmill.fi| |Ph: 1 250 383-9735 torben@netmill.fi| +----------------------------------------------------------------+

« previous php.general (#15401) next »