note 26314 deleted from function.include by sniper

From: Date: Wed, 29 Jan 2003 04:16:32 +0000
Subject: note 26314 deleted from function.include by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-42996@lists.php.net to get a copy of this message
Be careful of taking arguments from the URL to pass to the include student. Just because you tack on a ".inc" or ".php" extension does not guaranty the safety or your includes. -- John Herren <jhherren at d2interactive dot comm> Thomas Swan <tswan at idigx dot comm> Take the following code example: show.php is a template file and it changes the contents by including another file specifed by the include_me variable. In show.php we have the line: include($DOCUMENT_ROOT. $include_me . ".php"); So, the URL, .../show.php?include_me=about, would display the contents of the /document/root/about.php file inside of the script. However, if you take the $include_me from the HTTP_GET_VARS, HTTP_POST_VARS, etc. array or directly (if you have globals visible), you run the risk of someone appending a null byte to the end of the string and effectively bypassing your arbitrary extension. On a UNIX system you could access the password file or some other critical file by using the URL http://host/show.php?include_me=../../../../../../path/to/file%00 The same method could be used to access files on a Win32 system or other platform. Since strings are null terminated, what you think would be a path to "/document/root/../../../../../../path/to/file%00.php" or "/document/root/../../../../../../path/to/file.php" (both of which should fail) now becomes "/document/root/../../../../../../path/to/file". This could be reduced to /path/to/file and will succeed if the file exists at the path given. Any easy way to solve this problem is to use the trim function. As it effectively produces a copy of the string, it will recognize the null as the end of string and return the string without the null. This will prevent the argument from being used to access and/or bypass your include method. A file_exists check is also useful, but will still return true even if it is a system file. Always assuming the worst from your users and guests can help you avoid some of the costlier mistakes of bad programming. -- John Herren, john at d2interactive dot com Thomas Swan, tswan at idigx dot com

« previous php.notes (#42996) next »