Re: Trying to avoid code exploits..
| From: | Yasuo Ohgaki | Date: | Tue, 31 Jul 2001 23:02:59 +0000 |
| Subject: | Re: Trying to avoid code exploits.. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-60532@lists.php.net to get a copy of this message | ||
"Meir Kriheli" <mksoft@netvision.net.il> wrote in message
news:200107311305.QAA02887@mailgw1.netvision.net.il...
> Hi,
> I need another pair of eyes to see if I've overlooked something.
SNIP
> so
> '{pass1}=={pass2}'
>
> is converted to
> '$GLOBALS['pass1']==$GLOBALS['pass2']'
>
> When to form is validated I'm running eval() to evaluate the
expression. I'm
> concerned that there's an exploit somewhere, maybe a user entering
some
> malicious data (I don't like using eval that often). But I'm not
using eval()
> directly on user entered data, and I can't see where it is possible.
Where pass1,pass2,etc came from? I guess from user and you set
register_globals=on in your php.ini. If this is the case, your script
is exploitable probably.
"register_globals=off" in your php.ini and use $HTTP_*_VARS.
If you want to protect values set by PHP also, I've posted sample
function at zend.com recently.
http://www.zend.com/codex.php?id=626&single=1
(Protect values (GET/POST/COOKIE) set by PHP)
Regards,
--
Yasuo Ohgaki