Re: inclusion safety
| From: | Zeev Suraski | Date: | Mon, 29 May 2000 18:47:20 +0000 |
| Subject: | Re: inclusion safety | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-561@lists.php.net to get a copy of this message | ||
On Mon, 29 May 2000, Jeroen Jochems wrote:
> <sorry for my bad english, i'm dutch)
>
> In a multiuser admin for a new site people are able to upload a file called
> content.inc that will be included in a index.php file. Users may only use 3
> (selfmade) functions in it that I say them. Is it possible to check if users
> don't use other functions? Or make sure they don't get executed? Else users
> will be able to mess up te whole server!
>
> I hope anyone can help me with this! Thank you!
You can't be sure at all about what's included in the file your users
upload. What you describe sounds horrible security wise - executing
ANYTHING that comes from an untrusted source is bad. Note that even if
their file only includes those 3 specific functions you're interested in,
there are no guarentees as to what their implementation looks like. A
function called ImHarmless() may very well call system("rm -rf /").
Zeev
--
Zeev Suraski <zeev@zend.com>
http://www.zend.com/