com web/php: Tweak regex to make it clearer: archive/entries/2012-05-06-1.xml
| From: | Rasmus Lerdorf | Date: | Sun, 06 May 2012 23:32:32 +0000 |
| Subject: | com web/php: Tweak regex to make it clearer: archive/entries/2012-05-06-1.xml | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-13470@lists.php.net to get a copy of this message | ||
Commit: ac1dfd4c18886d832b958b1eca4607a525a7a03b
Author: Rasmus Lerdorf <rasmus@php.net> Sun, 6 May 2012 16:32:32 -0700
Parents: ac483826269b9e97e818fbdadf69b9cfd9e5a4a8
Branches: master
Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=ac1dfd4c18886d832b958b1eca4607a525a7a03b
Log:
Tweak regex to make it clearer
Changed paths:
M archive/entries/2012-05-06-1.xml
Diff:
diff --git a/archive/entries/2012-05-06-1.xml b/archive/entries/2012-05-06-1.xml
index 46576c7..2ddb55a 100644
--- a/archive/entries/2012-05-06-1.xml
+++ b/archive/entries/2012-05-06-1.xml
@@ -16,17 +16,17 @@
issues. Again, people using mod_php or php-fpm are not affected.</p>
<p>
- One way to address these CGI issues is to throw away the query parameters if they
- contain a '-' and no '='. It can be done using Apache's mod_rewrite
like this:
+ One way to address these CGI issues is to reject the request if the query string
+ contains a '-' and no '='.. It can be done using Apache's mod_rewrite
like this:
<pre>
- RewriteCond %{QUERY_STRING} ^.*(%2d|-)[^=]+$ [NC]
- RewriteRule ^(.*) $1? [L]
+ RewriteCond %{QUERY_STRING} ^[^=]*$
+ RewriteCond %{QUERY_STRING} %2d|\- [NC]
+ RewriteRule .? - [F,L]
</pre>
Note that this will block otherwise safe requests like ?top-40 so if you
- are using mod_cgi and have query parameters that look like that, adjust your
- regex accordingly.</p>
+ have query parameters that look like that, adjust your regex accordingly.</p>
<p>Another set of releases are planned for Tuesday, May, 8th. These
releases will fix the CGI flaw and another CGI-related issue in