Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 06:39:10 +0000
Subject: Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
References: 1  Groups: php.dev php.general 
Request: Send a blank email to php-dev+get-32090@lists.php.net to get a copy of this message
AP>> You can also add a little (untested) embellishment such as: AP>> AP>> if ($userfile != basename($userfile)) AP>> { AP>> mail($WEBMASTER, "UserFile Attack Detected", "IP Address = Your mailbox gonna explode. $userfile never equals basename($userfile) - it contains full path as of now. -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#32090) next »