3 ms·
If thats the only validation on calls to file_get_contents, that could very easily be bypassed. Entering something like just "/etc/passwd" for example.
by philo23 10y ago
If thats the only validation on calls to file_get_contents, that could very easily be bypassed. Entering something like just "/etc/passwd" for example.
- milankragujevic 10y ago/etc != http :)
- philo23 10y agoAh yes, you're right. Totally mis-read the code. It'd still leave access to any files in the same (or sub) directory starting with http, which realistically would probably be none but still something to bear in mind.
- nitrogen 10y agoRight, best to check the whole URL. Something like "http/../../../etc/passwd" might get through otherwise.
- milankragujevic 10y agoLike.... $url = rawurldecode($_GET['url']); $url_without_protocol = str_replace(array('https://', 'http://'), '', $url); $protocol = (stristr($url, 'https://') ? 'https' : 'http'); $page = file_get_contents($protocol . '://' . $url_without_protocol);
- kh_hk 10y agoWhat about u = urlparse(url) if u.scheme not in ['http', 'https']: return 400