News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

PHP Security Blog:
Holes in most preg_match() filters
April 04, 2007 @ 07:15:50

On the PHP Security Log today, Stefan Esser points out some holes in most of the filters using preg_match that he's seen in examples and the like all around the web. Some of these things could cause issues that could breach the security of your application.

During the last week I was performing some audits and like so often it contained preg_match() filters that were not correct. Most PHP developers use ^ and $ within their regular expressions without actually reading the documentation about what they really achieve.

However the problem is, that the author of such a regular expression did not correctly read the documentation and mistakes the $ character for the definitive end of the subject.

According to Stefan, the actual documentation for the $ character in a regular expression isn't quite used that way. It does mean "the end" of the match but it can also match against a newline as well. His suggestions? Use the /D modifier on the end of the expression to match the real "the end" and not how it might match otherwise.

0 comments voice your opinion now!
security pregmatch filter match endofline clean security pregmatch filter match endofline clean


blog comments powered by Disqus

Similar Posts

PHPClasses.org: Lately in PHP podcast episode 41 - What Happened in the Security Attack to PHP.net?

Justin Siltervon\'s Blog: 5 Reasons not to use OSCommerce

Secunia.com: Mambo Unspecified Bypass Vulnerabilities

Anson Cheung's Blog: 8 essential checks on securing PHP

SitePoint PHP Blog: Good and Bad PHP Code


Community Events





Don't see your event here?
Let us know!


testing symfony2 opinion configure threedevsandamaybe release introduction refactor developer unittest list install community framework series interview code language laravel podcast

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework