note 26314 added to function.include
| From: | tswan at idigx dot com | Date: | Sat, 26 Oct 2002 04:54:26 +0000 |
| Subject: | note 26314 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-38574@lists.php.net to get a copy of this message | ||
Be careful of taking arguments from the URL to pass to the include student. Just because you tack
on a ".inc" or ".php" extension does not guaranty the safety or your includes.
--
John Herren <jhherren at d2interactive dot comm>
Thomas Swan <tswan at idigx dot comm>
Take the following code example:
show.php is a template file and it changes the contents by including another file specifed by the
include_me variable.
In show.php we have the line:
include($DOCUMENT_ROOT. $include_me . ".php");
So, the URL, .../show.php?include_me=about, would display the contents of the
/document/root/about.php file inside of the script.
However, if you take the $include_me from the HTTP_GET_VARS, HTTP_POST_VARS, etc. array or directly
(if you have globals visible), you run the risk of someone appending a null byte to the end of the
string and effectively bypassing your arbitrary extension.
On a UNIX system you could access the password file or some other critical file by using the URL
http://host/show.php?include_me=../../../../../../path/to/file%00
The same method could be used to access files on a Win32 system or other platform.
Since strings are null terminated, what you think would be a path to
"/document/root/../../../../../../path/to/file%00.php" or
"/document/root/../../../../../../path/to/file.php" (both of which should fail) now
becomes "/document/root/../../../../../../path/to/file". This could be reduced to
/path/to/file and will succeed if the file exists at the path given.
Any easy way to solve this problem is to use the trim function. As it effectively produces a copy
of the string, it will recognize the null as the end of string and return the string without the
null.
This will prevent the argument from being used to access and/or bypass your include method. A
file_exists check is also useful, but will still return true even if it is a system file.
Always assuming the worst from your users and guests can help you avoid some of the costlier
mistakes of bad programming.
--
John Herren, john at d2interactive dot com
Thomas Swan, tswan at idigx dot com
--
http://www.php.net/manual/en/function.include.php
http://master.php.net/manage/user-notes.php?action=edit+26314
http://master.php.net/manage/user-notes.php?action=delete+26314
http://master.php.net/manage/user-notes.php?action=reject+26314