note 29942 deleted from security.registerglobals by nlopess
| From: | nlopess@php.net | Date: | Sat, 10 Jan 2004 15:58:18 +0000 |
| Subject: | note 29942 deleted from security.registerglobals by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-63276@lists.php.net to get a copy of this message | ||
Note Submitter: Damon
----
I wrote this function to provide a way to automatically register the globals for form variables by
parsing the file for input names and textarea names. Since I have this function in an include file,
you need to pass it $_SERVER and $_GET/POST since these don't seem to be available to include
files...? Also, it uses djresonance's code to allow specifiing which variables to register
globally and thus allow access to ENV, COOKIE, etc. To top it all off, if it finds a variable passed
to the script that wasn't requested or wasn't found through parsing, it triggers a
security threat page.
<?php
function registerGlobals(&$serverVars, &$methodVars) {
$numArgs = func_num_args();
$args = func_get_args();
if ($numArgs == 2) {
$f = fopen($serverVars['SCRIPT_FILENAME'], 'r');
$buffer = '';
fclose($f);
$matches = array();
while (!feof($f))
$buffer .= fgets($f, 4096);
preg_match_all('/<(input|textarea).*?name=\"([\w]+)\".*?>/',
$buffer, $matches, PREG_PATTERN_ORDER);
foreach ($methodVars as $name => $value) {
if (in_array($name, $matches[2])) {
global ${$name};
${$name} = $methodVars[$name];
} else {
reportSecurityThreat($serverVars['REMOTE_ADDR']);
return false;
}
}
return true;
} elseif ($numArgs > 2) {
foreach ($methodVars as $name => $value) {
if (in_array($name, $args)) {
global ${$name};
${$name} = $methodVars[$name];
} else {
reportSecurityThreat($serverVars['REMOTE_ADDR']);
return false;
}
}
return true;
} else
die("Invalid number of arguments. Usage: registerGlobals(\$_SERVER, \$_GET/POST,
['var1', 'var2'...]);");
}
function reportSecurityThreat($ip) {
print <<<END
<table width="100%" height="100%">
<tr>
<td align="center" valign="center">
<table>
<tr>
<td align="center"><span style="font-family: Arial,
Helvetica, sans-serif; font-size: 30px; color: #ff0000;">Security Threat
Detected</span></td>
</tr>
<tr>
<td> </td>
</tr>
<tr>
<td><span style="font-family: Arial, Helvetica, sans-serif;
font-size: 15px; color: #000000;">This security threat from $ip has been logged and the
administrator notified.</span></td>
</tr>
</table>
</td>
</tr>
</table>
END;
}
?>