<?php
include_once $_SERVER['DOCUMENT_ROOT'] . '/include/shared-manual.inc';
$TOC = array();
$TOC_DEPRECATED = array();
$PARENTS = array();
include_once dirname(__FILE__) ."/toc/taint.detail.inc";
$setup = array (
  'home' => 
  array (
    0 => 'index.php',
    1 => 'PHP Manual',
  ),
  'head' => 
  array (
    0 => 'UTF-8',
    1 => 'tr',
  ),
  'this' => 
  array (
    0 => 'taint.detail.sinks.php',
    1 => 'Where taint raises warnings',
    2 => 'Where taint raises warnings',
  ),
  'up' => 
  array (
    0 => 'taint.detail.php',
    1 => 'Propagation and Checked Sinks',
  ),
  'prev' => 
  array (
    0 => 'taint.detail.basic.php',
    1 => 'How the taint mark is propagated',
  ),
  'next' => 
  array (
    0 => 'ref.taint.php',
    1 => 'Taint İşlevleri',
  ),
  'alternatives' => 
  array (
  ),
  'source' => 
  array (
    'lang' => 'en',
    'path' => 'reference/taint/detail.xml',
  ),
  'history' => 
  array (
  ),
);
$setup["toc"] = $TOC;
$setup["toc_deprecated"] = $TOC_DEPRECATED;
$setup["parents"] = $PARENTS;
manual_setup($setup);

contributors($setup);

?>
<div id="taint.detail.sinks" class="section">
  <h2 class="title">Where taint raises warnings</h2>
  <p class="simpara">
   When a tainted string reaches one of the sinks below, taint raises a
   warning (by default an <strong><code><a href="errorfunc.constants.php#constant.e-user-warning">E_USER_WARNING</a></code></strong>; the level is
   configurable via <a href="taint.configuration.php#ini.taint.error-level" class="link">taint.error_level</a>).
   Only top-level string arguments are inspected; dumping an array that
   merely contains tainted values does not warn.
  </p>
  <p class="para">
   <table class="doctable table">
    <caption><strong>Output sinks</strong></caption>
    
     <thead>
      <tr><th>Sink</th><th>Checked</th></tr>

     </thead>

     <tbody class="tbody">
      <tr>
       <td><code class="literal">echo</code>, <code class="literal">print</code></td>
       <td>the echoed/printed expression</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.printf.php" class="function">printf()</a></span>, <span class="function"><a href="function.vprintf.php" class="function">vprintf()</a></span></td>
       <td>the format string and the substituted values</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.print-r.php" class="function">print_r()</a></span>, <span class="function"><a href="function.var-dump.php" class="function">var_dump()</a></span>, <span class="function"><a href="function.var-export.php" class="function">var_export()</a></span></td>
       <td>the value being dumped, when it is a string</td>
      </tr>

      <tr>
       <td><code class="literal">exit</code>/<code class="literal">die</code> with a message</td>
       <td>the message</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.file-put-contents.php" class="function">file_put_contents()</a></span>, <span class="function"><a href="function.fwrite.php" class="function">fwrite()</a></span>, <span class="function"><a href="function.fputs.php" class="function">fputs()</a></span> to <code class="literal">php://output</code></td>
       <td>the data being written</td>
      </tr>

     </tbody>
    
   </table>

  </p>
  <p class="para">
   <table class="doctable table">
    <caption><strong>Filesystem sinks</strong></caption>
    
     <thead>
      <tr><th>Sink</th><th>Checked</th></tr>

     </thead>

     <tbody class="tbody">
      <tr>
       <td><span class="function"><a href="function.fopen.php" class="function">fopen()</a></span>, <span class="function"><a href="function.opendir.php" class="function">opendir()</a></span>, <span class="function"><a href="function.unlink.php" class="function">unlink()</a></span></td>
       <td>the path</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.file.php" class="function">file()</a></span>, <span class="function"><a href="function.readfile.php" class="function">readfile()</a></span>, <span class="function"><a href="function.file-get-contents.php" class="function">file_get_contents()</a></span>, <span class="function"><a href="function.highlight-file.php" class="function">highlight_file()</a></span>/<span class="function"><a href="function.show-source.php" class="function">show_source()</a></span></td>
       <td>the path</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.copy.php" class="function">copy()</a></span>, <span class="function"><a href="function.rename.php" class="function">rename()</a></span>, <span class="function"><a href="function.move-uploaded-file.php" class="function">move_uploaded_file()</a></span></td>
       <td>both the source and destination paths</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.mkdir.php" class="function">mkdir()</a></span>, <span class="function"><a href="function.rmdir.php" class="function">rmdir()</a></span>, <span class="function"><a href="function.touch.php" class="function">touch()</a></span></td>
       <td>the path</td>
      </tr>

      <tr>
       <td><code class="literal">include</code>, <code class="literal">include_once</code>, <code class="literal">require</code>, <code class="literal">require_once</code></td>
       <td>the file path</td>
      </tr>

     </tbody>
    
   </table>

  </p>
  <p class="para">
   <table class="doctable table">
    <caption><strong>SQL sinks</strong></caption>
    
     <thead>
      <tr><th>Sink</th><th>Checked</th></tr>

     </thead>

     <tbody class="tbody">
      <tr>
       <td><span class="function"><a href="mysqli.query.php" class="function">mysqli_query()</a></span>, <span class="function"><a href="mysqli.prepare.php" class="function">mysqli_prepare()</a></span>, <span class="function"><a href="mysqli.real-query.php" class="function">mysqli_real_query()</a></span>, <span class="function"><a href="mysqli.multi-query.php" class="function">mysqli_multi_query()</a></span></td>
       <td>the query string</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.mysql-query.php" class="function">mysql_query()</a></span>, <span class="function"><strong>sqlite_query()</strong></span>, <span class="function"><strong>sqlite_single_query()</strong></span>, <span class="function"><a href="function.oci-parse.php" class="function">oci_parse()</a></span>, <span class="function"><a href="function.pg-query.php" class="function">pg_query()</a></span>, <span class="function"><a href="function.pg-send-query.php" class="function">pg_send_query()</a></span></td>
       <td>the query string</td>
      </tr>

      <tr>
       <td><span class="methodname"><a href="mysqli.query.php" class="methodname">mysqli::query()</a></span>, <span class="methodname"><a href="mysqli.prepare.php" class="methodname">mysqli::prepare()</a></span>, <span class="methodname"><a href="mysqli.real-query.php" class="methodname">mysqli::real_query()</a></span>, <span class="methodname"><a href="mysqli.multi-query.php" class="methodname">mysqli::multi_query()</a></span></td>
       <td>the query string</td>
      </tr>

      <tr>
       <td><span class="methodname"><a href="pdo.query.php" class="methodname">PDO::query()</a></span>, <span class="methodname"><a href="pdo.prepare.php" class="methodname">PDO::prepare()</a></span>, <span class="methodname"><a href="pdo.exec.php" class="methodname">PDO::exec()</a></span></td>
       <td>the query string</td>
      </tr>

      <tr>
       <td><span class="methodname"><a href="sqlite3.query.php" class="methodname">SQLite3::query()</a></span>, <span class="methodname"><a href="sqlite3.prepare.php" class="methodname">SQLite3::prepare()</a></span>, <span class="methodname"><a href="sqlite3.exec.php" class="methodname">SQLite3::exec()</a></span>, <span class="methodname"><strong>SQLiteDatabase::query()</strong></span>, <span class="methodname"><strong>SQLiteDatabase::singleQuery()</strong></span></td>
       <td>the query string</td>
      </tr>

     </tbody>
    
   </table>

  </p>
  <p class="para">
   <table class="doctable table">
    <caption><strong>Command execution sinks</strong></caption>
    
     <thead>
      <tr><th>Sink</th><th>Checked</th></tr>

     </thead>

     <tbody class="tbody">
      <tr>
       <td><span class="function"><a href="function.exec.php" class="function">exec()</a></span>, <span class="function"><a href="function.system.php" class="function">system()</a></span>, <span class="function"><a href="function.passthru.php" class="function">passthru()</a></span>, <span class="function"><a href="function.shell-exec.php" class="function">shell_exec()</a></span> (including the backtick operator)</td>
       <td>the command string</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.proc-open.php" class="function">proc_open()</a></span>, <span class="function"><a href="function.popen.php" class="function">popen()</a></span></td>
       <td>the command string</td>
      </tr>

      <tr>
       <td><code class="literal">eval</code></td>
       <td>the evaluated code</td>
      </tr>

      <tr>
       <td>dynamic calls such as <code class="literal">$func()</code>, <code class="literal">$obj-&gt;$method()</code>, <span class="function"><a href="function.call-user-func.php" class="function">call_user_func()</a></span>, array callables</td>
       <td>the function/method/class name being resolved</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.preg-match.php" class="function">preg_match()</a></span>, <span class="function"><a href="function.preg-match-all.php" class="function">preg_match_all()</a></span>, <span class="function"><a href="function.preg-replace.php" class="function">preg_replace()</a></span>, <span class="function"><a href="function.preg-split.php" class="function">preg_split()</a></span>, <span class="function"><a href="function.preg-grep.php" class="function">preg_grep()</a></span>, <span class="function"><a href="function.preg-replace-callback.php" class="function">preg_replace_callback()</a></span></td>
       <td>the pattern (and the callback name for <span class="function"><a href="function.preg-replace-callback.php" class="function">preg_replace_callback()</a></span>)</td>
      </tr>

     </tbody>
    
   </table>

  </p>
  <p class="para">
   <table class="doctable table">
    <caption><strong>Header and cookie sinks</strong></caption>
    
     <thead>
      <tr><th>Sink</th><th>Checked</th></tr>

     </thead>

     <tbody class="tbody">
      <tr>
       <td><span class="function"><a href="function.header.php" class="function">header()</a></span></td>
       <td>the header string</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.setcookie.php" class="function">setcookie()</a></span>, <span class="function"><a href="function.setrawcookie.php" class="function">setrawcookie()</a></span></td>
       <td>the cookie name and value</td>
      </tr>

     </tbody>
    
   </table>

  </p>
  <p class="para">
   <table class="doctable table">
    <caption><strong>Other sinks</strong></caption>
    
     <thead>
      <tr><th>Sink</th><th>Checked</th></tr>

     </thead>

     <tbody class="tbody">
      <tr>
       <td><span class="function"><a href="function.unserialize.php" class="function">unserialize()</a></span></td>
       <td>the serialized string</td>
      </tr>

      <tr>
       <td><span class="function"><a href="function.mail.php" class="function">mail()</a></span></td>
       <td>to, subject, additional parameters and additional headers (the message body is content and is not checked)</td>
      </tr>

     </tbody>
    
   </table>

  </p>
  <p class="simpara">
   Warnings follow the format
   <code class="literal">function_name() [sink]: message</code>, where
   <code class="literal">sink</code> identifies the checked operation (for example
   <code class="literal">echo</code>, <code class="literal">include</code> or the function name) and
   the message describes what was found to be possibly tainted.
  </p>
 </div><?php manual_footer($setup); ?>