Re: Re: PHP taint support: first results
| From: | M. Sokolewicz | Date: | Fri, 05 Oct 2007 16:45:43 +0000 |
| Subject: | Re: Re: PHP taint support: first results | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-32653@lists.php.net to get a copy of this message | ||
(Wietse Venema) wrote:
laurent jouanneau:(Wietse Venema) wrote:In that case, I suppose you would not be using echo, so there is no problem. You wouldn't? So, when outputting a script-generated pdf file, how would you do that if not using echo? (and thus also not print since that's pretty much the exact same thing)To give an idea of the functionality, consider the following program with an obvious HTML injection bug:A PHP application doesn't always generate HTML : it can generate JSON, CSV, PDF etc.. In this case, we don't have to call htmlspecialchars etc..<?php $username = $_GET['username']; echo "Welcome back, $username\n"; ?>With default .ini settings, this program does exactly what the programmer wrote: it echos the contents of the username request attribute, including all the malicious HTML code that an attacker may have supplied along with it. When I change one .ini setting:taint_error_level = E_WARNINGthe program produces the same output, but it also produces a warning:Warning: echo(): Argument contains data that is not converted with htmlspecialchars() or htmlentities() in /path/to/script on line 3
WietseIs this warning appearing also when you want to output datas other than HTML ? If no, how your code guess the output type ? If yes, how can we disable this warning in pages which produce JSON etc. ?