Re: inclusion safety
| From: | Chris Moyer | Date: | Mon, 29 May 2000 18:38:52 +0000 |
| Subject: | Re: inclusion safety | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-568@lists.php.net to get a copy of this message | ||
On Mon, May 29, 2000 at 09:20:23PM +0200, Jeroen Jochems wrote:
> But how do I check for the valid functions?
>
> Jeroen Jochems
You make sure they are OK by only allowing certain functions... perhaps like so...
<select name='function'>
<option value='vak'>Vak function</option>
<option value='foo'>Foo FUnction/option>
</select>
Then when that is submitted, you can check it again, if you are worried
about someone sneaking a variable in a URL or a cookie...
if($function != 'vak' && $function != 'foo'){
echo "Sorry that's an invalid function, try again";
} else{
switch($function){
case "vak":
?>
Ok, pick argument one...
<form... >
<select name='arg1'>
<option value='1'>One</option>
<option value='2'>Two</option>
</select>
<input type=text name='arg2'>
break;
case "foo":
...
}
}
Then you can check the input again. The drop downs would be great if there are
limited number of possible arguments. Otherwise you will want to do some checking
on the string. You need to look at your functions and determine what content needs
to be allowable and not allow other values to be accepted. Arg2 is an email address,
search the archives for a Regexp to make sure it is an email adress... etc. Then
write the whole function call out to the file, and start the process again with
the next function.
> >
> > Someone else mentioned something similar to this:
> > Have the user create the file using your scripts, and various form.
> > 1. The first form allows you to pick what function to put in next.
> > 2. Then the form for that function promts the user for the appropriate
> > arguemnts
> > 3. Then you check the input for appropriatness.
> > Check that each argument is the right type, maybe do strip_tags()
> > and addslashes to it?
> > 4. Add that to the file, and return to step one until the user
> > has created their whole file.
> >
> > This way, it easy to control what is in that file, and also easier to
> > check for abuse.
> >
--
-- Chris Moyer -- cmoyer@chekinc.com --
PHP Developer -- Chek.com