©
This document uses PHP Chinese website manual Release
由于 PHP 的文件系统操作是基于 C 语言的函数的,所以它可能会以您意想不到的方式处理 Null 字符。 Null字符在 C 语言中用于标识字符串结束,一个完整的字符串是从其开头到遇见 Null 字符为止。 以下代码演示了类似的攻击:
Example #1 会被 Null 字符问题攻击的代码
<?php
$file = $_GET [ 'file' ]; // "../../etc/passwd\0"
if ( file_exists ( '/home/wwwrun/' . $file . '.php' )) {
// file_exists will return true as the file /home/wwwrun/../../etc/passwd exists
include '/home/wwwrun/' . $file . '.php' ;
// the file /etc/passwd will be included
}
?>
因此,任何用于操作文件系统的字符串(译注:特别是程序外部输入的字符串)都必须经过适当的检查。以下是上述例子的改进版本:
Example #2 验证输入的正确做法
<?php
$file = $_GET [ 'file' ];
// 对字符串进行白名单检查
switch ( $file ) {
case 'main' :
case 'foo' :
case 'bar' :
include '/home/wwwrun/include/' . $file . '.php' ;
break;
default:
include '/home/wwwrun/include/main.php' ;
}
?>
[#1] cornernote [at] gmail.com [2015-04-21 04:26:31]
clean input of null bytes:
<?php
$clean = str_replace(chr(0), '', $input);
?>
[#2] J.D. Grimes [2014-11-05 20:34:40]
This issue has been fixed for file_exists(): https://bugs.php.net/bug.php?id=39863
It still exists for include|require(_once) as of this writing.
[#3] Anonymous [2014-05-09 14:51:05]
Looks like this issue was fixed in PHP 5.3 https://bugs.php.net/bug.php?id=39863
[#4] kpobococ at gmail dot com [2009-05-16 12:25:34]
Since problems with null bytes do not stretch to regular string functions, this should be enough to ensure no GET parameter contains them any more:
<?php
function getVar($name)
{
$value = isset($_GET[$name]) ? $_GET[$name] : null;
if (is_string($value)) {
$value = str_replace("\0", '', $value);
}
}
?>
Modifying this to work with other superglobals should not be a problem, so I will leave it up to you.