note 28853 added to security.errors

From: Date: Sun, 26 Jan 2003 02:05:32 +0000
Subject: note 28853 added to security.errors
Groups: php.notes 
Request: Send a blank email to php-notes+get-42748@lists.php.net to get a copy of this message
In Example 5-13 above, it could be exploited, consider it again: <?php if ($username) { // Not initialized or checked before usage $good_login = 1; } if ($good_login == 1) { // If above test fails, not initialized or checked before usage fpassthru ("/highly/sensitive/data/index.html"); } ?> if this page was called "dosomething.php" you could exploit it by passing the url: "/dosomething.php?good_login=1" A good fix would be: <?php $good_login = 0; // set user bad so it cant pass from url query. if ($username) { // Not initialized or checked before usage $good_login = 1; } if ($good_login == 1) { // If above test fails, not initialized or checked before usage fpassthru ("/highly/sensitive/data/index.html"); } ?> Just a thought. http://www.404LewZerZ.com/ -- http://www.php.net/manual/en/security.errors.php http://master.php.net/manage/user-notes.php?action=edit+28853 http://master.php.net/manage/user-notes.php?action=delete+28853 http://master.php.net/manage/user-notes.php?action=reject+28853

« previous php.notes (#42748) next »