note 48286 deleted from function.trim by betz

From: Date: Sat, 18 Dec 2004 17:07:59 +0000
Subject: note 48286 deleted from function.trim by betz
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-81981@lists.php.net to get a copy of this message
Note Submitter: raul at navenetworks dot com ---- Hi! I think this could help programmers they want to be sure that when they receive the variables by GET,POST or in another way that they can't be attacked or make the server in a security problem, as it happens in the PhpBB bug (all version before 2.0.11). Imagine you have 2 variables you get them by GET or POST, we will assume that you have global ON in the php.ini setup working with apache: $page and $domain <?php require("security.php"); // at the beginning $page = protect($page); $domain= protect($domain); // ... now you can use the variables without any problem... ... ?> And the security.php include the secure next code: <?php function protect($cadena) { $cadena2= ""; $posi=0; // normally only a-z,A-Z,0-9 allowed. // modify it as you could need... while ( ($cadena[$posi]>='a' && $cadena[$posi]<='z') || ($cadena[$posi]>='A' && $cadena[$posi]<='Z') || ($cadena[$posi]>='0' && $cadena[$posi]<='9') ){ $cadena2[$posi]= $cadena[$posi]; $posi++; // block MAX SIZE for string. // don't use STRLEN or // they could run commands as system() if the php/apache hasn't this command or other exec disabled functions... if($posi>500) return join($cadena2,""); } return join($cadena2,""); } ?> I hope this help to program better and increase the security programming your apps. If you need more info don't hesitate contact me raul@navenetworks.com. I speak english, french and spanish. Raul Mate Galan Ceo Navenetworks www.navenetworks.com www.buenhospedaje.com ---- Reason: bad code

« previous php.notes (#81981) next »