note 29942 deleted from security.registerglobals by nlopess

From: Date: Sat, 10 Jan 2004 15:58:18 +0000
Subject: note 29942 deleted from security.registerglobals by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-63276@lists.php.net to get a copy of this message
Note Submitter: Damon ---- I wrote this function to provide a way to automatically register the globals for form variables by parsing the file for input names and textarea names. Since I have this function in an include file, you need to pass it $_SERVER and $_GET/POST since these don't seem to be available to include files...? Also, it uses djresonance's code to allow specifiing which variables to register globally and thus allow access to ENV, COOKIE, etc. To top it all off, if it finds a variable passed to the script that wasn't requested or wasn't found through parsing, it triggers a security threat page. <?php function registerGlobals(&$serverVars, &$methodVars) { $numArgs = func_num_args(); $args = func_get_args(); if ($numArgs == 2) { $f = fopen($serverVars['SCRIPT_FILENAME'], 'r'); $buffer = ''; fclose($f); $matches = array(); while (!feof($f)) $buffer .= fgets($f, 4096); preg_match_all('/<(input|textarea).*?name=\"([\w]+)\".*?>/', $buffer, $matches, PREG_PATTERN_ORDER); foreach ($methodVars as $name => $value) { if (in_array($name, $matches[2])) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } elseif ($numArgs > 2) { foreach ($methodVars as $name => $value) { if (in_array($name, $args)) { global ${$name}; ${$name} = $methodVars[$name]; } else { reportSecurityThreat($serverVars['REMOTE_ADDR']); return false; } } return true; } else die("Invalid number of arguments. Usage: registerGlobals(\$_SERVER, \$_GET/POST, ['var1', 'var2'...]);"); } function reportSecurityThreat($ip) { print <<<END <table width="100%" height="100%"> <tr> <td align="center" valign="center"> <table> <tr> <td align="center"><span style="font-family: Arial, Helvetica, sans-serif; font-size: 30px; color: #ff0000;">Security Threat Detected</span></td> </tr> <tr> <td>&nbsp;</td> </tr> <tr> <td><span style="font-family: Arial, Helvetica, sans-serif; font-size: 15px; color: #000000;">This security threat from $ip has been logged and the administrator notified.</span></td> </tr> </table> </td> </tr> </table> END; } ?>

« previous php.notes (#63276) next »