note 28853 deleted from security.errors by vincent

From: Date: Sun, 10 Aug 2003 20:19:57 +0000
Subject: note 28853 deleted from security.errors by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-53825@lists.php.net to get a copy of this message
Note Submitter: da404LewZer@hotmail.com ---- In Example 5-13 above, it could be exploited, consider it again: <?php if ($username) { // Not initialized or checked before usage $good_login = 1; } if ($good_login == 1) { // If above test fails, not initialized or checked before usage fpassthru ("/highly/sensitive/data/index.html"); } ?> if this page was called "dosomething.php" you could exploit it by passing the url: "/dosomething.php?good_login=1" A good fix would be: <?php $good_login = 0; // set user bad so it cant pass from url query. if ($username) { // Not initialized or checked before usage $good_login = 1; } if ($good_login == 1) { // If above test fails, not initialized or checked before usage fpassthru ("/highly/sensitive/data/index.html"); } ?> Just a thought. http://www.404LewZerZ.com/

« previous php.notes (#53825) next »