Re: Arbitrary file disclosure through PHP file upload

From: Date: Wed, 06 Sep 2000 00:23:05 +0000
Subject: Re: Arbitrary file disclosure through PHP file upload
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-15406@lists.php.net to get a copy of this message
Lars Torben Wilson wrote: > Stanislav Malyshev writes: > > LTW>> $safepath = get_cfg_var('upload_tmp_dir') . '/' . > > LTW>> basename($userfile); > > That's closer to the point. Now why won't PHP really do it? > Do you mean 'do it' as in why doesn't PHP handle this so the user > doesn't have to? I dunno. I believe perhaps it should--at least to the > point of doing some simple checks to ensure that the file lives in the > upload directory and matches the location which PHP comes up with for > the temp files and perhaps issuing a warning if needed. HP doesn't do it, because it can't do it. The PHP engine doesn't know in advance what FORM vars the script will try to use as uploaded tmp file names. Therefore it can't do any checks itself. A better solution for the future would be to separate FORM vars from vars that PHP has set which contain information about tmp file locations. Making it impossible for a munged FORM var to pretend to be a PHP generated tmp file location. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15406) next »