Re: Arbitrary file disclosure through PHP file upload
| From: | Simon Edwards | Date: | Wed, 06 Sep 2000 00:23:05 +0000 |
| Subject: | Re: Arbitrary file disclosure through PHP file upload | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15406@lists.php.net to get a copy of this message | ||
Lars Torben Wilson wrote:
> Stanislav Malyshev writes:
> > LTW>> $safepath = get_cfg_var('upload_tmp_dir') . '/' .
> > LTW>> basename($userfile);
> > That's closer to the point. Now why won't PHP really do it?
> Do you mean 'do it' as in why doesn't PHP handle this so the user
> doesn't have to? I dunno. I believe perhaps it should--at least to the
> point of doing some simple checks to ensure that the file lives in the
> upload directory and matches the location which PHP comes up with for
> the temp files and perhaps issuing a warning if needed.
HP doesn't do it, because it can't do it. The PHP engine doesn't know in
advance what FORM vars the script will try to use as uploaded tmp file
names. Therefore it can't do any checks itself.
A better solution for the future would be to separate FORM vars from
vars that PHP has set which contain information about tmp file
locations. Making it impossible for a munged FORM var to pretend to be a
PHP generated tmp file location.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990