Security feature or bug?
| From: | bill | Date: | Wed, 28 Jun 2000 14:44:10 +0000 |
| Subject: | Security feature or bug? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-3562@lists.php.net to get a copy of this message | ||
A client uses a PHP page to upload a newsletter to an area outside the
web directory tree. The client also uploads images that go with the
newsletter to the same area.
The image tags in the newsletter are relative urls like
<IMG SRC="calendar.gif">
So, the web browser expects to find them in the same directory as the
newsletter.
I was surprised to find that when I use a PHP page to "serve up" the
newsletter from outside the web directory tree, it dished up the images
just fine. They displayed correctly in Netscape 4.7x and IE 5.
Even more interesting, if you right-click on a displayed image and
choose View Image, it displays ascii garbage on the screen. Kind of a
funny way to prevent image theft, eh?
So, what's happening? Should I change it?
Here's a code snippet from the PHP page that dishes up the newsletter:
Header("Content-Type: text/html");
Header("Content-length: " . filesize($filedir . $PATH_INFO));
Header("Content-Description: $filetype");
readfile($filedir . $PATH_INFO));
//This file is called thus:
http://mydomain.com/newsletterserverpage.php3/mynewsletter.html
Thanks for the help.
bill