Re: Security of PHP code
| From: | Steve Werby | Date: | Wed, 04 Jul 2001 16:21:55 +0000 |
| Subject: | Re: Security of PHP code | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-56192@lists.php.net to get a copy of this message | ||
"Jon Haworth" <jhaworth@witanjardine.co.uk> wrote:
> Yes, I would have thought this would do it:
>
> if (strstr($file, "/usr/local/apache/htdocs/") {
> show_source($file);
> } else {
> echo "File must be in /usr/local/apache/htdocs!";
> }
>
> Modify as appropriate.
>
> Have I missed anything, or will this do the trick?
Something along those lines will work. Without some kind of limitations
built in, the page will be able to load any file that's world-readable so
it's a good idea to limit access to certain directories or hardcode the
directory you want to give access to.
--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/