Security feature or bug?

From: Date: Wed, 28 Jun 2000 14:44:10 +0000
Subject: Security feature or bug?
Groups: php.general 
Request: Send a blank email to php-general+get-3562@lists.php.net to get a copy of this message
A client uses a PHP page to upload a newsletter to an area outside the web directory tree. The client also uploads images that go with the newsletter to the same area. The image tags in the newsletter are relative urls like <IMG SRC="calendar.gif"> So, the web browser expects to find them in the same directory as the newsletter. I was surprised to find that when I use a PHP page to "serve up" the newsletter from outside the web directory tree, it dished up the images just fine. They displayed correctly in Netscape 4.7x and IE 5. Even more interesting, if you right-click on a displayed image and choose View Image, it displays ascii garbage on the screen. Kind of a funny way to prevent image theft, eh? So, what's happening? Should I change it? Here's a code snippet from the PHP page that dishes up the newsletter: Header("Content-Type: text/html"); Header("Content-length: " . filesize($filedir . $PATH_INFO)); Header("Content-Description: $filetype"); readfile($filedir . $PATH_INFO)); //This file is called thus: http://mydomain.com/newsletterserverpage.php3/mynewsletter.html Thanks for the help. bill

« previous php.general (#3562) next »