note 31446 added to function.include
| From: | damien at NOSPAM dot atypix dot com | Date: | Tue, 22 Apr 2003 14:29:35 +0000 |
| Subject: | note 31446 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46930@lists.php.net to get a copy of this message | ||
You may think its secure to set an include base before dynamic include file. but its not sufficient.
try this index.php?file=../../../etc/passwd
so use this function instead include($file) if $file come from user.
<?
function secure_include($file)
{
$include_base="/home/includes/";
$file=str_replace("../","",$file);
$file=str_replace("..","",$file);
$file=str_replace("//","/",$file);
if(file_exists($include_base.$file))
{
include_once($include_base.$file);
}
}
//SECURE USER INCLUDE
secure_include($_REQUEST["file"]);
?>
NOTE: you must use the same tips for fopen(), file()... use with user path.
--
http://www.php.net/manual/en/function.include.php
http://master.php.net/manage/user-notes.php?action=edit+31446
http://master.php.net/manage/user-notes.php?action=delete+31446
http://master.php.net/manage/user-notes.php?action=reject+31446