The script looks very dangerous, but I cannot tell anyone coz I'm blacklisted!

From: Date: Thu, 30 Nov 2006 22:53:47 +0000
Subject: The script looks very dangerous, but I cannot tell anyone coz I'm blacklisted!
Groups: php.mirrors 
Request: Send a blank email to php-mirrors+get-33417@lists.php.net to get a copy of this message
Hello. I *cannot* post notes, we are on a huge NAT network, I wrote about this once already, still blocked.. http://www.dnsstuff.com/tools/ip4r.ch?ip=81.208.60.201 As you see even the lists say "Dynamic IP Addresses","Dynamic/Residential IP range"... This below was my dangerous spam (trying to add to the imagejpeg page). Maybe you should warn people not to use that dangerous script: I can't. Maybe you should use blacklists as they are supposed to be used. Not blocking dynamic IPs. ___________________________________________________________________ PHpContrib [ a t ] eSurfers D o t COM ___________________________________________________________________ The script by webmaster at jongliertreff dot de looks very dangerous to me!! His image.php file parses the path to the images direclty from the url parameters without any control!! Users could write urls like: image.php?image_name=password&style=../../../etc/ to delete any important file, easily erasing your site, or doing much worse (gaining computer control)!! I would recommend (1+2+3): 1) not passing paths in the url, ever. Pass filename with no path (and follow point 2 on them) 2) checking user parameters for ../, etc
    there are PHP functions just for this:
    http://it2.php.net/manual/en/function.escapeshellcmd.php
3) test the $style parameter for allowed values and discard anything you would not expect (but still you need to check $image_name)
This is not paranoia, I swear, it's for real! :) ___________________________________________________________________ Francesco M. Munafo' PANGOO design Via Vittor Pisani 10 20124 - Milano Italy francesco@pangoo.it http://pangoo.it/

« previous php.mirrors (#33417) next »