Re: inclusion safety

From: Date: Mon, 29 May 2000 19:07:28 +0000
Subject: Re: inclusion safety
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-565@lists.php.net to get a copy of this message
No, this is a part of the file i expect the users to upload: ------------------- colom(1,o); vak(11,name,o); l("www.linux.org","linux","11","t"); l("www.linux.org","linux","11","t"); l("www.linux.org","linux","11","t"); vak(11,name,s); -------------- The functions are declared in de index.php file that includes the content.inc... Jeroen Jochems Webfreak Internet Services Chief Executive Officer jeroen@webfreak.nl www.webfreak.nl ----- Original Message ----- From: "James Lyon" <james.lyon@aztec.co.uk> To: "Jeroen Jochems" <jeroen@jochems.net>; "PHP General List" <php-general@lists.php.net> Sent: Monday, May 29, 2000 9:04 PM Subject: Re: [PHP-GENERAL] inclusion safety > > <sorry for my bad english, i'm dutch) > > Sorry for *my* bad English -- I'm a mathematician :-)) > > > > In a multiuser admin for a new site people are able to upload a file called > > content.inc that will be included in a index.php file. Users may only use 3 > > (selfmade) functions in it that I say them. Is it possible to check if users > > don't use other functions? Or make sure they don't get executed? Else users > > will be able to mess up te whole server! > > As the other person said, this is very dangerous for security. > > You would have to parse the file uploaded and check its syntax, semantics, > verify it's all correct and then include it -- and you're still running a risk. > > The best thing is to ask the user a question on a web page and then use PHP to > write your own file on the server from one of 3 pre-defined files so you can > only ever get a file that you knew about in advance -- whatever the user tries > to do to the web page they will either get one of the scripts you wanted them to > get, or they will break it and it won't work at all. > > This is safer. > > Hope this helps, > James. >

« previous php.general (#565) next »