Re: Trying to avoid code exploits..

From: Date: Tue, 31 Jul 2001 23:02:59 +0000
Subject: Re: Trying to avoid code exploits..
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-60532@lists.php.net to get a copy of this message
"Meir Kriheli" <mksoft@netvision.net.il> wrote in message news:200107311305.QAA02887@mailgw1.netvision.net.il... > Hi, > I need another pair of eyes to see if I've overlooked something. SNIP > so > '{pass1}=={pass2}' > > is converted to > '$GLOBALS['pass1']==$GLOBALS['pass2']' > > When to form is validated I'm running eval() to evaluate the expression. I'm > concerned that there's an exploit somewhere, maybe a user entering some > malicious data (I don't like using eval that often). But I'm not using eval() > directly on user entered data, and I can't see where it is possible. Where pass1,pass2,etc came from? I guess from user and you set register_globals=on in your php.ini. If this is the case, your script is exploitable probably. "register_globals=off" in your php.ini and use $HTTP_*_VARS. If you want to protect values set by PHP also, I've posted sample function at zend.com recently. http://www.zend.com/codex.php?id=626&single=1 (Protect values (GET/POST/COOKIE) set by PHP) Regards, -- Yasuo Ohgaki

« previous php.general (#60532) next »