note 28853 deleted from security.errors by vincent
| From: | vincent@php.net | Date: | Sun, 10 Aug 2003 20:19:57 +0000 |
| Subject: | note 28853 deleted from security.errors by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-53825@lists.php.net to get a copy of this message | ||
Note Submitter: da404LewZer@hotmail.com
----
In Example 5-13 above, it could be exploited, consider it again:
<?php
if ($username) { // Not initialized or checked before usage
$good_login = 1;
}
if ($good_login == 1) { // If above test fails, not initialized or checked before usage
fpassthru ("/highly/sensitive/data/index.html");
}
?>
if this page was called "dosomething.php" you could exploit it by passing the url:
"/dosomething.php?good_login=1"
A good fix would be:
<?php
$good_login = 0; // set user bad so it cant pass from url query.
if ($username) { // Not initialized or checked before usage
$good_login = 1;
}
if ($good_login == 1) { // If above test fails, not initialized or checked before usage
fpassthru ("/highly/sensitive/data/index.html");
}
?>
Just a thought.
http://www.404LewZerZ.com/