Re: opendir security hole

From: Date: Mon, 03 Jun 2002 20:01:29 +0000
Subject: Re: opendir security hole
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-100463@lists.php.net to get a copy of this message
On Mon, Jun 03, 2002 at 08:41:37PM +0100, Stuart Dallas wrote: > > Surely a regular expression is overkill for this? It would be more efficient to > use str_replace()... > > $dir = str_replace('..', '', $dir); Sure. But you'd need to do two replaces. First for '../' then for '..' Not a big deal. Don't know if that's faster than preg or not. I'm used to preg, so am biased toward writing them. Alas... Enjoy, --Dan -- PHP classes that make web design easier SQL Solution | Layout Solution | Form Solution sqlsolution.info | layoutsolution.info | formsolution.info T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y 4015 7 Av #4AJ, Brooklyn NY v: 718-854-0335 f: 718-854-0409

« previous php.general (#100463) next »