note 29942 added to security.registerglobals
| From: | Damon at rack1 dot php dot net | Date: | Sat, 01 Mar 2003 18:25:26 +0000 |
| Subject: | note 29942 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-44702@lists.php.net to get a copy of this message | ||
I wrote this function to provide a way to automatically register the globals for form variables by
parsing the file for input names and textarea names. Since I have this function in an include file,
you need to pass it $_SERVER and $_GET/POST since these don't seem to be available to include
files...? Also, it uses djresonance's code to allow specifiing which variables to register
globally and thus allow access to ENV, COOKIE, etc. To top it all off, if it finds a variable passed
to the script that wasn't requested or wasn't found through parsing, it triggers a
security threat page.
<?php
function registerGlobals(&$serverVars, &$methodVars) {
$numArgs = func_num_args();
$args = func_get_args();
if ($numArgs == 2) {
$f = fopen($serverVars['SCRIPT_FILENAME'], 'r');
$buffer = '';
$matches = array();
while (!feof($f))
$buffer .= fgets($f, 4096);
preg_match_all('/<(input|textarea).*?name=\"([\w]+)\".*?>/',
$buffer, $matches, PREG_PATTERN_ORDER);
foreach ($methodVars as $name => $value) {
if (in_array($name, $matches[2])) {
global ${$name};
${$name} = $methodVars[$name];
} else {
reportSecurityThreat($serverVars['REMOTE_ADDR']);
return false;
}
}
return true;
} elseif ($numArgs > 2) {
foreach ($methodVars as $name => $value) {
if (in_array($name, $args)) {
global ${$name};
${$name} = $methodVars[$name];
} else {
reportSecurityThreat($serverVars['REMOTE_ADDR']);
return false;
}
}
return true;
} else
die("Invalid number of arguments. Usage: registerGlobals(\$_SERVER, \$_GET/POST,
['var1', 'var2'...]);");
}
function reportSecurityThreat($ip) {
print <<<END
<table width="100%" height="100%">
<tr>
<td align="center" valign="center">
<table>
<tr>
<td align="center"><span style="font-family: Arial,
Helvetica, sans-serif; font-size: 30px; color: #ff0000;">Security Threat
Detected</span></td>
</tr>
<tr>
<td> </td>
</tr>
<tr>
<td><span style="font-family: Arial, Helvetica, sans-serif;
font-size: 15px; color: #000000;">This security threat from $ip has been logged and the
administrator notified.</span></td>
</tr>
</table>
</td>
</tr>
</table>
END;
}
?>
--
http://www.php.net/manual/en/security.registerglobals.php
http://master.php.net/manage/user-notes.php?action=edit+29942
http://master.php.net/manage/user-notes.php?action=delete+29942
http://master.php.net/manage/user-notes.php?action=reject+29942