Re: Security of PHP code
| From: | Phil Driscoll | Date: | Wed, 04 Jul 2001 16:32:58 +0000 |
| Subject: | Re: Security of PHP code | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-56197@lists.php.net to get a copy of this message | ||
Surely the lesson here is to NEVER NEVER NEVER write PHP code which accepts a
filename of any kind as one of its arguments. Yes, it will make some of your
code a bit less versatile and more long winded, but you can bet your bottom
dollar that someone can find a crafty way around whatever syntax checking you
do.
Cheers
--
Phil Driscoll