php - inject code into $_SERVER ?
Christophe Vandeplas <[email protected]> Tue, 01 Feb 2005 10:16:48 +0100
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
Hello
I am coding a kind of weblogin system that adapts the firewall of a
gateway for logged users so that they can access another network.
The weblogin system is written in php4 on a apache2 webserver running on a debian system.
to adapt the firewall I made a simple script, let's call it
firewallAuth. This script needs 1 argument, the ip that needs to be
added in the firewall.
Now the only way to do this in php is to use the 'exec()' function.
The ip of the user is stored in $_SERVER['REMOTE_ADDR'].
To get root rights (I need them to adapt my firewall) i use sudo. (the
php user can only run the firewallAuth command with sudo)
So I just do this in php code:
exec("sudo /home/firewall/firewallAuth ".$_SERVER['REMOTE_ADDR']);
My question is now: is there any (known) way for a user to inject arbitrary code
into this _SERVER global? (and thus execute this code on the server with root permissions)
or am I not-to-unsafe to use it?
Should I perform some more checks on the $_SERVER['REMOTE_ADDR'] before using it as argument?
Thanks for the comments.
--
-------------------------------------
Christophe Vandeplas
GSM: +32 (0)486/64.10.33
email: christophe(at)vandeplas(dot)com
http://www.vandeplas.com
GnuPG:1024D/14913897: 66BD A9EB 0357 D80F 20D4 D698 3B2B E562 1491 3897
-------------------------------------
*** PLEASE ***
"Never send mass-mails/forward to this email address.
Please add the email-address to the BCC field (Blind Carbon Copy)
or send the mail separately to me."
--
-------------------------------------
Christophe 'ElCascador' Vandeplas
GSM: +32 (0)486/64.10.33
email: christophe(at)vandeplas(dot)com
http://www.vandeplas.com
GnuPG:1024D/14913897: 66BD A9EB 0357 D80F 20D4 D698 3B2B E562 1491 3897
-------------------------------------
*** PLEASE ***
"Never send mass-mails/forward to this email address.
Please add the email-address to the BCC field (Blind Carbon Copy)
or send the mail separately to me."
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQBB/0kAOyvlYhSROJcRAgQtAJ9tw8M7hdxPldR+/i6UQpndo1SvrwCdG0Z0 ZT0YBFkb34M8XFKGoIJ71Q4= =fdMn -----END PGP SIGNATURE-----