note 29953 added to function.include

From: Date: Sun, 02 Mar 2003 01:29:13 +0000
Subject: note 29953 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-44717@lists.php.net to get a copy of this message
To add further emphasis to the above security notes, I came across a user a while ago who had implemented include($pg) and made $pg visible, i.e., his links showed up as index.php?$pg=page.html. To complicate matters, url_fopen was enabled, so an attacker was able to include a geocities page by url which included nothing but the php command <?php system($cmd); ?> By crafting the url to specify the page and command, the attacker was able to do WHATEVER HE WANTED on the server. I'm assuming he had the same right the webserver had, which luckily was not running as root. The attacker was stupid enough to launch a DoS attack, which allowed us to catch it quickly and correct the problem. Be very very careful with includes. Never let a visitor specify your include variables. -- http://www.php.net/manual/en/function.include.php http://master.php.net/manage/user-notes.php?action=edit+29953 http://master.php.net/manage/user-notes.php?action=delete+29953 http://master.php.net/manage/user-notes.php?action=reject+29953

« previous php.notes (#44717) next »