Re: opendir security hole
| From: | Analysis & Solutions | Date: | Mon, 03 Jun 2002 20:01:29 +0000 |
| Subject: | Re: opendir security hole | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-100463@lists.php.net to get a copy of this message | ||
On Mon, Jun 03, 2002 at 08:41:37PM +0100, Stuart Dallas wrote:
>
> Surely a regular expression is overkill for this? It would be more efficient to
> use str_replace()...
>
> $dir = str_replace('..', '', $dir);
Sure. But you'd need to do two replaces. First for '../' then for '..'
Not a big deal. Don't know if that's faster than preg or not. I'm used
to preg, so am biased toward writing them. Alas...
Enjoy,
--Dan
--
PHP classes that make web design easier
SQL Solution | Layout Solution | Form Solution
sqlsolution.info | layoutsolution.info | formsolution.info
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
4015 7 Av #4AJ, Brooklyn NY v: 718-854-0335 f: 718-854-0409