Re: Security of PHP code

From: Date: Wed, 04 Jul 2001 16:21:55 +0000
Subject: Re: Security of PHP code
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-56192@lists.php.net to get a copy of this message
"Jon Haworth" <jhaworth@witanjardine.co.uk> wrote: > Yes, I would have thought this would do it: > > if (strstr($file, "/usr/local/apache/htdocs/") { > show_source($file); > } else { > echo "File must be in /usr/local/apache/htdocs!"; > } > > Modify as appropriate. > > Have I missed anything, or will this do the trick? Something along those lines will work. Without some kind of limitations built in, the page will be able to load any file that's world-readable so it's a good idea to limit access to certain directories or hardcode the directory you want to give access to. -- Steve Werby President, Befriend Internet Services LLC http://www.befriend.com/

« previous php.general (#56192) next »