Re: Security of PHP code
| From: | Sascha Schumann | Date: | Wed, 04 Jul 2001 16:18:44 +0000 |
| Subject: | Re: Security of PHP code | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-56194@lists.php.net to get a copy of this message | ||
On Wed, 4 Jul 2001, Steve Werby wrote:
> "Jon Haworth" <jhaworth@witanjardine.co.uk> wrote:
> > Yes, I would have thought this would do it:
> >
> > if (strstr($file, "/usr/local/apache/htdocs/") {
> > show_source($file);
[..]
> Something along those lines will work. Without some kind of limitations
> built in, the page will be able to load any file that's world-readable so
> it's a good idea to limit access to certain directories or hardcode the
> directory you want to give access to.
Imagine someone passing in
/usr/local/apache/htdocs/../../../../etc/passwd as path..
- Sascha Experience IRCG
http://schumann.cx/ http://schumann.cx/ircg