Re: inclusion safety
| From: | Webfreak.nl helpdesk | Date: | Mon, 29 May 2000 19:07:28 +0000 |
| Subject: | Re: inclusion safety | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-565@lists.php.net to get a copy of this message | ||
No, this is a part of the file i expect the users to upload:
-------------------
colom(1,o);
vak(11,name,o);
l("www.linux.org","linux","11","t");
l("www.linux.org","linux","11","t");
l("www.linux.org","linux","11","t");
vak(11,name,s);
--------------
The functions are declared in de index.php file that includes the
content.inc...
Jeroen Jochems
Webfreak Internet Services
Chief Executive Officer
jeroen@webfreak.nl
www.webfreak.nl
----- Original Message -----
From: "James Lyon" <james.lyon@aztec.co.uk>
To: "Jeroen Jochems" <jeroen@jochems.net>; "PHP General List"
<php-general@lists.php.net>
Sent: Monday, May 29, 2000 9:04 PM
Subject: Re: [PHP-GENERAL] inclusion safety
> > <sorry for my bad english, i'm dutch)
>
> Sorry for *my* bad English -- I'm a mathematician :-))
>
>
> > In a multiuser admin for a new site people are able to upload a file
called
> > content.inc that will be included in a index.php file. Users may only
use 3
> > (selfmade) functions in it that I say them. Is it possible to check if
users
> > don't use other functions? Or make sure they don't get executed? Else
users
> > will be able to mess up te whole server!
>
> As the other person said, this is very dangerous for security.
>
> You would have to parse the file uploaded and check its syntax, semantics,
> verify it's all correct and then include it -- and you're still running a
risk.
>
> The best thing is to ask the user a question on a web page and then use
PHP to
> write your own file on the server from one of 3 pre-defined files so you
can
> only ever get a file that you knew about in advance -- whatever the user
tries
> to do to the web page they will either get one of the scripts you wanted
them to
> get, or they will break it and it won't work at all.
>
> This is safer.
>
> Hope this helps,
> James.
>