note 29942 added to security.registerglobals

From: Date: Sat, 01 Mar 2003 18:25:26 +0000
Subject: note 29942 added to security.registerglobals
Groups: php.notes 
Request: Send a blank email to php-notes+get-44702@lists.php.net to get a copy of this message
I wrote this function to provide a way to automatically register the globals for form variables by parsing the file for input names and textarea names. Since I have this function in an include file, you need to pass it $_SERVER and $_GET/POST since these don't seem to be available to include files...? Also, it uses djresonance's code to allow specifiing which variables to register globally and thus allow access to ENV, COOKIE, etc. To top it all off, if it finds a variable passed to the script that wasn't requested or wasn't found through parsing, it triggers a security threat page. <?php function registerGlobals(&$serverVars, &$methodVars) { $numArgs = func_num_args(); $args = func_get_args(); if ($numArgs == 2) { $f = fopen($serverVars['SCRIPT_FILENAME'], 'r'); $buffer = ''; $matches = array(); while (!feof($f)) $buffer .= fgets($f, 4096); preg_match_all('/<(input|textarea).*?name=\"([\w]+)\".*?>/', $buffer, $matches, PREG_PATTERN_ORDER); foreach ($methodVars as $name => $value) { if (in_array($name, $matches[2])) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } elseif ($numArgs > 2) { foreach ($methodVars as $name => $value) { if (in_array($name, $args)) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } else die("Invalid number of arguments. Usage: registerGlobals(\$_SERVER, \$_GET/POST, ['var1', 'var2'...]);"); } function reportSecurityThreat($ip) { print <<<END <table width="100%" height="100%"> <tr> <td align="center" valign="center"> <table> <tr> <td align="center"><span style="font-family: Arial, Helvetica, sans-serif; font-size: 30px; color: #ff0000;">Security Threat Detected</span></td> </tr> <tr> <td>&nbsp;</td> </tr> <tr> <td><span style="font-family: Arial, Helvetica, sans-serif; font-size: 15px; color: #000000;">This security threat from $ip has been logged and the administrator notified.</span></td> </tr> </table> </td> </tr> </table> END; } ?> -- http://www.php.net/manual/en/security.registerglobals.php http://master.php.net/manage/user-notes.php?action=edit+29942 http://master.php.net/manage/user-notes.php?action=delete+29942 http://master.php.net/manage/user-notes.php?action=reject+29942

« previous php.notes (#44702) next »