Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
| From: | Simon Edwards | Date: | Tue, 05 Sep 2000 02:46:32 +0000 |
| Subject: | Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15214@lists.php.net to get a copy of this message | ||
Andreas Pour wrote:
> You can also add a little (untested) embellishment such as:
> if ($userfile != basename($userfile))
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
if($userfile != ($safepath.'/'.basename($userfile)))
> {
> mail($WEBMASTER, "UserFile Attack Detected", "IP Address =
> '$REMOTE_ADDR'\nUser id = ....");
> echo "Foiled again<BR>";
> }
> else
> {
> process the data
> }
That should work better.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990