Re: inclusion safety
| From: | James Lyon | Date: | Mon, 29 May 2000 19:04:10 +0000 |
| Subject: | Re: inclusion safety | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-563@lists.php.net to get a copy of this message | ||
> <sorry for my bad english, i'm dutch)
Sorry for *my* bad English -- I'm a mathematician :-))
> In a multiuser admin for a new site people are able to upload a file called
> content.inc that will be included in a index.php file. Users may only use 3
> (selfmade) functions in it that I say them. Is it possible to check if users
> don't use other functions? Or make sure they don't get executed? Else users
> will be able to mess up te whole server!
As the other person said, this is very dangerous for security.
You would have to parse the file uploaded and check its syntax, semantics,
verify it's all correct and then include it -- and you're still running a risk.
The best thing is to ask the user a question on a web page and then use PHP to
write your own file on the server from one of 3 pre-defined files so you can
only ever get a file that you knew about in advance -- whatever the user tries
to do to the web page they will either get one of the scripts you wanted them to
get, or they will break it and it won't work at all.
This is safer.
Hope this helps,
James.