note 48323 deleted from function.trim by tularis
| From: | tularis@php.net | Date: | Sun, 19 Dec 2004 16:30:41 +0000 |
| Subject: | note 48323 deleted from function.trim by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-82048@lists.php.net to get a copy of this message | ||
Note Submitter: raul at buenhospedaje dot com
----
Hi!
I am sure this will help to improve security in your programming feature in php.
Be carefull using trim() function or any string function with variables passed through GET or POST
or with global setting enabled in php, because they could run commands without authorization.
For example if the variable is $example by GET:
http://www.yourdomain.com/?example=%2527%
252esystem(chr(112)%252echr(115)%252echr(32)
%252echr(97)%252echr(117)%252echr(120))%252
e%2527
And then hackers could run a simple code it will allow to run
the command "ps aux" in this example without our
authorizations.
(see more info at: http://www.phpbbhacks.com/forums/viewtopic.php?p=170850)
So the solution could be to analyse first the routines before processing it in the php files.
function filtering($cad) {
$cad2= "";
$posi=0;
while ( ($cad[$posi]=='.') || ($cad[$posi]>='a' &&
$cad[$posi]<='z') || ($cad[$posi]>='A' &&
$cad[$posi]<='Z') || ($cad[$posi]>='0' &&
$cad[$posi]<='9') ){
$cad2[$posi]= $cad[$posi];
$posi++;
if($posi>500) break;
}
if(empty($cad2)) return $cad2; else
return join($cad2,"");
}
To use the function just in the php code define it and to all your variables:
<?php
// begin code
$example=filtering($example);
$code = filtering($code);
...
... your code NOW you are more safe...
?>
I hope you like this info,
Raul Mate Galan
Ceo Buenhospedaje
www.buenhospedaje.com