Re: php - inject code into $_SERVER ?
Christophe Vandeplas <[email protected]> Tue, 01 Feb 2005 20:59:22 +0100
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
--=-bC3lSc42cQZ5B+dnStfr
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable
On Tue, 2005-02-01 at 20:22 +0200, Alex 'CAVE' Cernat wrote:
> of course, it's not paranoid to do some regexep like
> ^[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}$ before passing it to
> system call
Thanks a lot to everyone who responded,
I'll do a little filter on 10.10.x.x (because this is the dhcp range of
my dhcpd)
Maybe it's a good idea to also parse the dhcp leases to check that the
ip has been attributed by the dhcp server...
--=20
-------------------------------------
Christophe 'ElCascador' Vandeplas
GSM: +32 (0)486/64.10.33
email: christophe(at)vandeplas(dot)com
http://www.vandeplas.com
GnuPG:1024D/14913897: 66BD A9EB 0357 D80F 20D4 D698 3B2B E562 1491 3897
-------------------------------------
*** PLEASE ***
"Never send mass-mails/forward to this email address.
Please add the email-address to the BCC field (Blind Carbon Copy)
or send the mail separately to me."
--=-bC3lSc42cQZ5B+dnStfr
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQBB/9+aOyvlYhSROJcRAt1QAJ9JvQamzXFDj35PDxyO4NISgb9nCgCggO0u
gBUUZBagefi/mzHvRNuuHbw=
=gsDn
-----END PGP SIGNATURE-----
--=-bC3lSc42cQZ5B+dnStfr--