note 28853 added to security.errors
| From: | da404LewZer at hotmail dot com | Date: | Sun, 26 Jan 2003 02:05:32 +0000 |
| Subject: | note 28853 added to security.errors | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-42748@lists.php.net to get a copy of this message | ||
In Example 5-13 above, it could be exploited, consider it again:
<?php
if ($username) { // Not initialized or checked before usage
$good_login = 1;
}
if ($good_login == 1) { // If above test fails, not initialized or checked before usage
fpassthru ("/highly/sensitive/data/index.html");
}
?>
if this page was called "dosomething.php" you could exploit it by passing the url:
"/dosomething.php?good_login=1"
A good fix would be:
<?php
$good_login = 0; // set user bad so it cant pass from url query.
if ($username) { // Not initialized or checked before usage
$good_login = 1;
}
if ($good_login == 1) { // If above test fails, not initialized or checked before usage
fpassthru ("/highly/sensitive/data/index.html");
}
?>
Just a thought.
http://www.404LewZerZ.com/
--
http://www.php.net/manual/en/security.errors.php
http://master.php.net/manage/user-notes.php?action=edit+28853
http://master.php.net/manage/user-notes.php?action=delete+28853
http://master.php.net/manage/user-notes.php?action=reject+28853