Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
| From: | Stanislav Malyshev | Date: | Tue, 05 Sep 2000 06:39:10 +0000 |
| Subject: | Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-dev+get-32090@lists.php.net to get a copy of this message | ||
AP>> You can also add a little (untested) embellishment such as:
AP>>
AP>> if ($userfile != basename($userfile))
AP>> {
AP>> mail($WEBMASTER, "UserFile Attack Detected", "IP Address =
Your mailbox gonna explode. $userfile never equals basename($userfile) -
it contains full path as of now.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106