note 29942 modified in security.registerglobals by vincent

From: Date: Fri, 26 Sep 2003 06:44:36 +0000
Subject: note 29942 modified in security.registerglobals by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-57151@lists.php.net to get a copy of this message
I wrote this function to provide a way to automatically register the globals for form variables by parsing the file for input names and textarea names. Since I have this function in an include file, you need to pass it $_SERVER and $_GET/POST since these don't seem to be available to include files...? Also, it uses djresonance's code to allow specifiing which variables to register globally and thus allow access to ENV, COOKIE, etc. To top it all off, if it finds a variable passed to the script that wasn't requested or wasn't found through parsing, it triggers a security threat page. <?php function registerGlobals(&$serverVars, &$methodVars) { $numArgs = func_num_args(); $args = func_get_args(); if ($numArgs == 2) { $f = fopen($serverVars['SCRIPT_FILENAME'], 'r'); $buffer = ''; fclose($f); $matches = array(); while (!feof($f)) $buffer .= fgets($f, 4096); preg_match_all('/<(input|textarea).*?name=\"([\w]+)\".*?>/', $buffer, $matches, PREG_PATTERN_ORDER); foreach ($methodVars as $name => $value) { if (in_array($name, $matches[2])) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } elseif ($numArgs > 2) { foreach ($methodVars as $name => $value) { if (in_array($name, $args)) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } else die("Invalid number of arguments. Usage: registerGlobals(\$_SERVER, \$_GET/POST, ['var1', 'var2'...]);"); } function reportSecurityThreat($ip) { print <<<END <table width="100%" height="100%"> <tr> <td align="center" valign="center"> <table> <tr> <td align="center"><span style="font-family: Arial, Helvetica, sans-serif; font-size: 30px; color: #ff0000;">Security Threat Detected</span></td> </tr> <tr> <td>&nbsp;</td> </tr> <tr> <td><span style="font-family: Arial, Helvetica, sans-serif; font-size: 15px; color: #000000;">This security threat from $ip has been logged and the administrator notified.</span></td> </tr> </table> </td> </tr> </table> END; } ?> --was-- I wrote this function to provide a way to automatically register the globals for form variables by parsing the file for input names and textarea names. Since I have this function in an include file, you need to pass it $_SERVER and $_GET/POST since these don't seem to be available to include files...? Also, it uses djresonance's code to allow specifiing which variables to register globally and thus allow access to ENV, COOKIE, etc. To top it all off, if it finds a variable passed to the script that wasn't requested or wasn't found through parsing, it triggers a security threat page. <?php function registerGlobals(&$serverVars, &$methodVars) { $numArgs = func_num_args(); $args = func_get_args(); if ($numArgs == 2) { $f = fopen($serverVars['SCRIPT_FILENAME'], 'r'); $buffer = ''; $matches = array(); while (!feof($f)) $buffer .= fgets($f, 4096); preg_match_all('/<(input|textarea).*?name=\"([\w]+)\".*?>/', $buffer, $matches, PREG_PATTERN_ORDER); foreach ($methodVars as $name => $value) { if (in_array($name, $matches[2])) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } elseif ($numArgs > 2) { foreach ($methodVars as $name => $value) { if (in_array($name, $args)) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } else die("Invalid number of arguments. Usage: registerGlobals(\$_SERVER, \$_GET/POST, ['var1', 'var2'...]);"); } function reportSecurityThreat($ip) { print <<<END <table width="100%" height="100%"> <tr> <td align="center" valign="center"> <table> <tr> <td align="center"><span style="font-family: Arial, Helvetica, sans-serif; font-size: 30px; color: #ff0000;">Security Threat Detected</span></td> </tr> <tr> <td>&nbsp;</td> </tr> <tr> <td><span style="font-family: Arial, Helvetica, sans-serif; font-size: 15px; color: #000000;">This security threat from $ip has been logged and the administrator notified.</span></td> </tr> </table> </td> </tr> </table> END; } ?> http://www.php.net/manual/en/security.registerglobals.php

« previous php.notes (#57151) next »