Re: inclusion safety

From: Date: Mon, 29 May 2000 19:40:27 +0000
Subject: Re: inclusion safety
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-569@lists.php.net to get a copy of this message
> No, this is a part of the file i expect the users to upload: > ------------------- > colom(1,o); > vak(11,name,o); > l("www.linux.org","linux","11","t"); > l("www.linux.org","linux","11","t"); > l("www.linux.org","linux","11","t"); > vak(11,name,s); > -------------- > > The functions are declared in de index.php file that includes the > content.inc... Just write the above to a file from a script when required, but don't let the user provide the file. By making the options *structured* it limits the user to things you want them to do. Don't underestimate how much a hacker can exploit an open door, even if you think you've blocked all the nasties!!!

« previous php.general (#569) next »