cvs: phpdoc /en/chapters security.xml
| From: | Andrew Lindeman | Date: | Thu, 27 Mar 2003 02:35:18 +0000 |
| Subject: | cvs: phpdoc /en/chapters security.xml | ||
| Groups: | php.doc | ||
| Request: | Send a blank email to phpdoc+get-969352331@lists.php.net to get a copy of this message | ||
alindeman Wed Mar 26 21:35:18 2003 EDT
Modified files:
/phpdoc/en/chapters security.xml
Log:
fixing bug #22915
Index: phpdoc/en/chapters/security.xml
diff -u phpdoc/en/chapters/security.xml:1.51 phpdoc/en/chapters/security.xml:1.52
--- phpdoc/en/chapters/security.xml:1.51 Sun Jan 19 05:30:14 2003
+++ phpdoc/en/chapters/security.xml Wed Mar 26 21:35:18 2003
@@ -1,5 +1,5 @@
<?xml version="1.0" encoding="iso-8859-1"?>
-<!-- $Revision: 1.51 $ -->
+<!-- $Revision: 1.52 $ -->
<chapter id="security">
<title>Security</title>
@@ -1011,7 +1011,7 @@
$good_login = 1;
}
if ($good_login == 1) { // If above test fails, not initialized or checked before usage
- fpassthru ("/highly/sensitive/data/index.html");
+ readfile ("/highly/sensitive/data/index.html");
}
?>
]]>
@@ -1046,7 +1046,7 @@
}
if ($good_login == 1) { // can be forged by a user in get/post/cookies,
- fpassthru ("/highly/sensitive/data/index.html");
+ readfile ("/highly/sensitive/data/index.html");
}
?>
]]>
@@ -1060,7 +1060,7 @@
if($_COOKIE['username']){
// can only come from a cookie, forged or otherwise
$good_login = 1;
- fpassthru ("/highly/sensitive/data/index.html");
+ readfile ("/highly/sensitive/data/index.html");
}
?>
]]>
@@ -1083,7 +1083,7 @@
!$_GET['username'] ) {
// Perform other checks to validate the user name...
$good_login = 1;
- fpassthru ("/highly/sensitive/data/index.html");
+ readfile ("/highly/sensitive/data/index.html");
} else {
mail("admin@example.com", "Possible breakin attempt",
$_SERVER['REMOTE_ADDR']);
echo "Security violation, admin has been alerted.";