The script looks very dangerous, but I cannot tell anyone coz I'm blacklisted!
| From: | Francesco Munafo' | PANGOO design | Date: | Thu, 30 Nov 2006 22:53:47 +0000 |
| Subject: | The script looks very dangerous, but I cannot tell anyone coz I'm blacklisted! | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-33417@lists.php.net to get a copy of this message | ||
Hello.
I *cannot* post notes, we are on a huge NAT network, I wrote about this once already, still blocked..
http://www.dnsstuff.com/tools/ip4r.ch?ip=81.208.60.201
As you see even the lists say "Dynamic IP Addresses","Dynamic/Residential IP range"...
This below was my dangerous spam (trying to add to the imagejpeg page).
Maybe you should warn people not to use that dangerous script: I can't.
Maybe you should use blacklists as they are supposed to be used.
Not blocking dynamic IPs.
___________________________________________________________________
PHpContrib [ a t ] eSurfers D o t COM
___________________________________________________________________
The script by webmaster at jongliertreff dot de looks very dangerous to me!!
His image.php file parses the path to the images direclty from the url parameters without any control!!
Users could write urls like:
image.php?image_name=password&style=../../../etc/
to delete any important file, easily erasing your site, or doing much worse (gaining computer control)!!
I would recommend (1+2+3):
1) not passing paths in the url, ever. Pass filename with no path (and follow point 2 on them)
2) checking user parameters for ../, etc
there are PHP functions just for this:
http://it2.php.net/manual/en/function.escapeshellcmd.php
3) test the $style parameter for allowed values and discard anything you would not expect (but still you need to check $image_name)
This is not paranoia, I swear, it's for real!
:)
___________________________________________________________________
Francesco M. Munafo'
PANGOO design
Via Vittor Pisani 10
20124 - Milano
Italy
francesco@pangoo.it
http://pangoo.it/