Re: Security of PHP code
| From: | (Delbono) | Date: | Wed, 04 Jul 2001 16:25:52 +0000 |
| Subject: | Re: Security of PHP code | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-56196@lists.php.net to get a copy of this message | ||
Yes, I supposed there could be that eventuality...
I supposed or hoped that wasn't a valid path.
> /usr/local/apache/htdocs/../../../../etc/passwd as path..
I'm not very practice of paths... actually
> On Wed, 4 Jul 2001, Steve Werby wrote:
>
> > "Jon Haworth" <jhaworth@witanjardine.co.uk> wrote:
> > > Yes, I would have thought this would do it:
> > >
> > > if (strstr($file, "/usr/local/apache/htdocs/") {
> > > show_source($file);
> [..]
> > Something along those lines will work. Without some kind of limitations
> > built in, the page will be able to load any file that's world-readable
so
> > it's a good idea to limit access to certain directories or hardcode the
> > directory you want to give access to.
>
> Imagine someone passing in
> /usr/local/apache/htdocs/../../../../etc/passwd as path..
>
> - Sascha Experience IRCG
> http://schumann.cx/
> http://schumann.cx/ircg
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>