Re: Security of PHP code

From: Date: Wed, 04 Jul 2001 18:32:39 +0000
Subject: Re: Security of PHP code
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-56215@lists.php.net to get a copy of this message
On Wednesday 04 July 2001 16:12, ReDucTor wrote: > http://sourceforge.net/source.php?page_url=/source.php look at > that... No problem. Have a look at what is done before the show_source () call. That script *is* safe :) > > It is not how secure PHP is, it is how well YOU protect it. > > For example = make this line show_source($file); then go to your page > > like file.php?file=/etc/passwd and you're freaked! -- Christian Reiniger LGDC Webmaster (http://lgdc.sunsite.dk/) Pretty cool, the kind of power information technology puts in our hands these days. - Securityfocus on probing 36000000 hosts for known problems in 3 weeks

« previous php.general (#56215) next »