Re: php - inject code into $_SERVER ?

Lucas Holt <[email protected]> Tue, 1 Feb 2005 18:05:03 -0500
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
On Feb 1, 2005, at 2:59 PM, Christophe Vandeplas wrote:

> On Tue, 2005-02-01 at 20:22 +0200, Alex 'CAVE' Cernat wrote:
>> of course, it's not paranoid to do some regexep like
>> ^[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}$ before passing it to
>> system call
>
> Thanks a lot to everyone who responded,
> I'll do a little filter on 10.10.x.x (because this is the dhcp range of
> my dhcpd)
> Maybe it's a good idea to also parse the dhcp leases to check that the
> ip has been attributed by the dhcp server...
>
>

Also consider ip6 addresses if there is a possibility they will be used 
on your local network in the future.

Lucas Holt
[email protected]
________________________________________________________
FoolishGames.com  (Jewel Fan Site)
JustJournal.com (Free blogging)
FoolishGames.net (Enemy Territory IoM site)