Re: Re: [Fwd: (SRADV00001) Arbitrary filedisclosurethrough PHP file upload]
| From: | Ron Chmara | Date: | Tue, 05 Sep 2000 00:44:56 +0000 |
| Subject: | Re: Re: [Fwd: (SRADV00001) Arbitrary filedisclosurethrough PHP file upload] | ||
| References: | 1 2 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-general+get-15191@lists.php.net to get a copy of this message | ||
Ron Chmara wrote:
> I am
> talking about a security model where it is assumed that the server
> files themselves may be uploaded.
Sorry to be replying to myself, but:
Would this work for most users, without having to patch, to make sure
they are operating on a user uploaded file?
<?
$validtmpdir = get_cfg_var("upload_tmp_dir");
/* make sure you're using an uploaded file */
if (strstr ("$validtmpdir", "$userfile") != 0){
copy ("$userfile" "/place/to/put/uploaded/file");
.....
} else {
echo "Not an uploaded file!";
exit;
}
?>
-Bop
--
Brought to you from iBop the iMac, a MacOS, Win95, Win98, LinuxPPC machine,
which is currently in MacOS land. Your bopping may vary.