note 48286 deleted from function.trim by betz
| From: | betz@php.net | Date: | Sat, 18 Dec 2004 17:07:59 +0000 |
| Subject: | note 48286 deleted from function.trim by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-81981@lists.php.net to get a copy of this message | ||
Note Submitter: raul at navenetworks dot com
----
Hi!
I think this could help programmers they want to be sure that when they receive the variables by
GET,POST or in another way that they can't be attacked or make the server in a security
problem, as it happens in the PhpBB bug (all version before 2.0.11).
Imagine you have 2 variables you get them by GET or POST, we will assume that you have global ON in
the php.ini setup working with apache: $page and $domain
<?php
require("security.php");
// at the beginning
$page = protect($page);
$domain= protect($domain);
// ... now you can use the variables without any problem...
...
?>
And the security.php include the secure next code:
<?php
function protect($cadena) {
$cadena2= "";
$posi=0;
// normally only a-z,A-Z,0-9 allowed.
// modify it as you could need...
while ( ($cadena[$posi]>='a' && $cadena[$posi]<='z') ||
($cadena[$posi]>='A' && $cadena[$posi]<='Z') ||
($cadena[$posi]>='0' && $cadena[$posi]<='9') ){
$cadena2[$posi]= $cadena[$posi];
$posi++;
// block MAX SIZE for string.
// don't use STRLEN or
// they could run commands as system() if the php/apache
hasn't this command or other exec disabled functions...
if($posi>500) return join($cadena2,"");
}
return join($cadena2,"");
}
?>
I hope this help to program better and increase the security programming your apps.
If you need more info don't hesitate contact me raul@navenetworks.com. I speak english, french
and spanish.
Raul Mate Galan
Ceo Navenetworks
www.navenetworks.com
www.buenhospedaje.com
----
Reason: bad code