note 48323 deleted from function.trim by tularis

From: Date: Sun, 19 Dec 2004 16:30:41 +0000
Subject: note 48323 deleted from function.trim by tularis
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-82048@lists.php.net to get a copy of this message
Note Submitter: raul at buenhospedaje dot com ---- Hi! I am sure this will help to improve security in your programming feature in php. Be carefull using trim() function or any string function with variables passed through GET or POST or with global setting enabled in php, because they could run commands without authorization. For example if the variable is $example by GET: http://www.yourdomain.com/?example=%2527% 252esystem(chr(112)%252echr(115)%252echr(32) %252echr(97)%252echr(117)%252echr(120))%252 e%2527 And then hackers could run a simple code it will allow to run the command "ps aux" in this example without our authorizations. (see more info at: http://www.phpbbhacks.com/forums/viewtopic.php?p=170850) So the solution could be to analyse first the routines before processing it in the php files. function filtering($cad) { $cad2= ""; $posi=0; while ( ($cad[$posi]=='.') || ($cad[$posi]>='a' && $cad[$posi]<='z') || ($cad[$posi]>='A' && $cad[$posi]<='Z') || ($cad[$posi]>='0' && $cad[$posi]<='9') ){ $cad2[$posi]= $cad[$posi]; $posi++; if($posi>500) break; } if(empty($cad2)) return $cad2; else return join($cad2,""); } To use the function just in the php code define it and to all your variables: <?php // begin code $example=filtering($example); $code = filtering($code); ... ... your code NOW you are more safe... ?> I hope you like this info, Raul Mate Galan Ceo Buenhospedaje www.buenhospedaje.com

« previous php.notes (#82048) next »