【问题标题】:PHP Downloading a file using url query - what are all the threats?PHP 使用 url 查询下载文件 - 有哪些威胁?
【发布时间】:2018-03-24 11:15:14
【问题描述】:

没有运气在互联网上找到答案,所以我想我会问专家。使用 url 查询下载文件会带来哪些安全威胁,例如这样的代码:

if(isset($_SERVER['QUERY_STRING']) && $_SERVER['QUERY_STRING'] != ""){
    $file = urldecode($_SERVER['QUERY_STRING']);
    if(file_exists("files/".$file)){
        header('Content-Description: File Transfer');
        header('Content-Type: application/octet-stream');
        header("Content-Transfer-Encoding: Binary");
        header('Content-Disposition: attachment; filename="'.basename($file).'"');
        header('Expires: 0');
        header('Cache-Control: must-revalidate');
        header('Pragma: public');
        header('Content-Length: ' . filesize("files/".$file));
        ob_clean();
        flush();
        readfile("files/".$file);
        exit;
    }
}

很容易受到诸如“?..\..\..\any\file\here”之类的查询字符串的攻击,但这还不是全部吗?这不能被一个if过滤掉吗?

    $file = urldecode($_SERVER['QUERY_STRING']);
    if(strpos($file, ".\\") !== false || strpos($file, "./") !== false){
        echo "No you won't get my system files";
        exit;
    }

如果没有“上传”功能,.htaccess 文件阻止访问 \files\ 目录和“if strpos”,那么这样安全吗?

编辑:错误的代码示例

【问题讨论】:

  • 请注意,聪明的黑客可以使用正斜杠绕过您的安全过滤器。这就是黑名单方法的问题:你无法找出所有可能的情况。

标签: php html apache security


【解决方案1】:

1) 你会受到..\..\..\any\file\here的攻击

2) 我建议您获取files/ 中所有子文件的列表。然后,如果请求的文件与这些文件中的任何一个都不匹配,则返回 404 错误代码。

PHP read sub-directories and loop through files how to?

【讨论】:

    猜你喜欢
    • 2011-08-28
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-03-27
    • 1970-01-01
    • 1970-01-01
    • 2022-11-03
    • 2020-10-15
    相关资源
    最近更新 更多