Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 02:46:32 +0000
Subject: Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
References: 1 2 3 4 5 6 7  Groups: php.general 
Request: Send a blank email to php-general+get-15214@lists.php.net to get a copy of this message
Andreas Pour wrote: > You can also add a little (untested) embellishment such as: > if ($userfile != basename($userfile)) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ if($userfile != ($safepath.'/'.basename($userfile))) > { > mail($WEBMASTER, "UserFile Attack Detected", "IP Address = > '$REMOTE_ADDR'\nUser id = ...."); > echo "Foiled again<BR>"; > } > else > { > process the data > } That should work better. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15214) next »