Re: Protecting Include remote files
| From: | stephan dot schoell at chhos dot mail dot abb dot com | Date: | Thu, 29 Jun 2000 14:05:13 +0000 |
| Subject: | Re: Protecting Include remote files | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-3806@lists.php.net to get a copy of this message | ||
It was just yesterday, that I noticed that I have the same problem with my site.
The difference is only that I do not work on different servers. But saying
index.php3?content=timetable.php3 which includes timetable.php3 in index.php3
opens the door to everyone. This way you can have your index.php3 include any
file, even harmful files that are not accessible directly (e.g. .htaccess). My
idea is the following (which I will implement before tomorrow!):
I build an array that contains all the "secure dirs" (directories with
potentially harmful or at least sensitive scripts, e.g. admin tools), check the
include string for any occurence of one of my "secure dirs" and act according to
the result I get.
<?php
$secure_dir[]="dir1";
$secure_dir[]="dir2";
// I even could get this list from a file in a password protected directory or
from a db table.
reset($secure_dir);
while (list($key, $dir) = each ($secure_dir)) {
if (strstr($content,$dir)) { // or maybe: if (strstr($HTTP_REFERER,$dir)) {
attack_handler(); // function that handles suspicious cases...
}
}
I haven't tested the code yet. Any comments would be appreciated.
Maybe others out there have even better ideas?!
-Steff
On Wed, 28 Jun 2000, Reuben D Budiardja wrote:
>
> Hi,
>
> I have two server running php. One of them connect with Oracle, and
> have been used for Php application for administration in my institution,
> and only a certain user can use it (let's call it server1). The second
> server is only a web server (server2).
>
> Now, I am creating an application in server1 (using database and stuff). I
> want to displayed to public, thus I include the application page in
> server2. So, in server2, I would have something like
> include ('http://server1.domain.com/blah.php3'); .
>
> My question is, can I protect that application in server1 (blah.php3) so
> that it cannot be included by anyone except by server2 ? I mean, if I know
> the URL address for the application in server1, I can use any server,
> serverX, to include that application in my page right? Is there anyway to
> avoid this?
Include in your bla.php3:
if $HTTP_REFERER <> server1
echo "Go away!"
R.V.
+-------------------------------------------------------------------------+
| Radek Vybiral Radek.Vybiral @ vsb.cz |
| Technical University of Ostrava http://www.vsb.cz/~l92494 |
| Czech Republic GSM: +420 602 473 670 |
| Projects: Admin on darksys.vsb.cz http://darksys.vsb.cz |
| NEW! Czech: Sluzby automobilistum http://www.automobil.cz |
| |
| J.W Goethe: "Prestoze svet stale pokracuje, mladi lide musi |
| vzdy zacinat od zacatku." |
+-------------------------------------------------------------------------+
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net