5 ms·
$url = 'https://hashcash.io/api/checkwork/' https://hashcash.io/api/checkwork/' . $_REQUEST['hashcashid'] . '?apikey=[YOUR-PRIVATE-KEY]'; $work = json_decode(
by a1a 12y ago
$url = 'https://hashcash.io/api/checkwork/' https://hashcash.io/api/checkwork/' . $_REQUEST['hashcashid'] . '?apikey=[YOUR-PRIVATE-KEY]'; $work = json_decode(file_get_contents($url));
Pretty sure this code is vulnerable to local file inclusion. Running file_get_contents on unchecked user input is a terrible idea, even more so coming from a "security solution".
- hippich 12y agoIt was quick and dirty example on how to use it. Frameworks usually expose builder function where you can pass query as and array/hash and that should be used. Do you have better example which will be clear about what happening and use pure PHP?
- deleted 12y ago[deleted]
- ars 12y agoAdd: if(strspn($_REQUEST['hashcashid'], 'abcdef0123456789-') != strlen($_REQUEST['hashcashid']) die('Invalid character.');
- 0x0 12y agoHow do you turn a prefix of "https://hashcash.io/" https://hashcash.io/" into a local file inclusion?