Re: inclusion safety

From: Date: Mon, 29 May 2000 18:47:20 +0000
Subject: Re: inclusion safety
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-561@lists.php.net to get a copy of this message
On Mon, 29 May 2000, Jeroen Jochems wrote: > <sorry for my bad english, i'm dutch) > > In a multiuser admin for a new site people are able to upload a file called > content.inc that will be included in a index.php file. Users may only use 3 > (selfmade) functions in it that I say them. Is it possible to check if users > don't use other functions? Or make sure they don't get executed? Else users > will be able to mess up te whole server! > > I hope anyone can help me with this! Thank you! You can't be sure at all about what's included in the file your users upload. What you describe sounds horrible security wise - executing ANYTHING that comes from an untrusted source is bad. Note that even if their file only includes those 3 specific functions you're interested in, there are no guarentees as to what their implementation looks like. A function called ImHarmless() may very well call system("rm -rf /"). Zeev -- Zeev Suraski <zeev@zend.com> http://www.zend.com/

« previous php.general (#561) next »