note 41333 deleted from function.readfile by aidan
| From: | aidan@php.net | Date: | Fri, 24 Sep 2004 01:28:06 +0000 |
| Subject: | note 41333 deleted from function.readfile by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-77280@lists.php.net to get a copy of this message | ||
Note Submitter: kazan at iastate dot edu
----
Say you have a script that is just wrapping pages with a template - if it contains a readfile() call
and someone gives in invalid data such as '/index.html' on a unix/unix-like machine (in
this specific case it was a OSX server) readfile will say "This file is in /", basically
it will tell you where the file is and whether it exists - so this could be theorectically used for
probing a system. I have corrected my script to avoid this.
However the fact that it behaves with way, and it's not documented that it does, is dangerous
security wise. This was discovered by one of my coworkers (The server admin) while we are getting
ready for a security audit - at a DOE Facility.