Re: inclusion safety
| From: | James Lyon | Date: | Mon, 29 May 2000 19:40:27 +0000 |
| Subject: | Re: inclusion safety | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-569@lists.php.net to get a copy of this message | ||
> No, this is a part of the file i expect the users to upload:
> -------------------
> colom(1,o);
> vak(11,name,o);
> l("www.linux.org","linux","11","t");
> l("www.linux.org","linux","11","t");
> l("www.linux.org","linux","11","t");
> vak(11,name,s);
> --------------
>
> The functions are declared in de index.php file that includes the
> content.inc...
Just write the above to a file from a script when required, but don't let the
user provide the file. By making the options *structured* it limits the user to
things you want them to do.
Don't underestimate how much a hacker can exploit an open door, even if you
think you've blocked all the nasties!!!