note 29953 added to function.include
| From: | bobgerman at NOSPAM dot irides dot com | Date: | Sun, 02 Mar 2003 01:29:13 +0000 |
| Subject: | note 29953 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-44717@lists.php.net to get a copy of this message | ||
To add further emphasis to the above security notes, I came across a user a while ago who had
implemented include($pg) and made $pg visible, i.e., his links showed up as index.php?$pg=page.html.
To complicate matters, url_fopen was enabled, so an attacker was able to include a geocities page
by url which included nothing but the php command
<?php system($cmd); ?>
By crafting the url to specify the page and command, the attacker was able to do WHATEVER HE WANTED
on the server. I'm assuming he had the same right the webserver had, which luckily was not
running as root.
The attacker was stupid enough to launch a DoS attack, which allowed us to catch it quickly and
correct the problem. Be very very careful with includes. Never let a visitor specify your include
variables.
--
http://www.php.net/manual/en/function.include.php
http://master.php.net/manage/user-notes.php?action=edit+29953
http://master.php.net/manage/user-notes.php?action=delete+29953
http://master.php.net/manage/user-notes.php?action=reject+29953