Re: hacks we should know about
| From: | Bob | Date: | Fri, 17 Aug 2001 04:17:31 +0000 |
| Subject: | Re: hacks we should know about | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-63123@lists.php.net to get a copy of this message | ||
rasmus, if password.inc is being parsed by php then how would you get the
code??? won't it just be a blank page??? oh i thought up one more ...
4. checking for html tags and php scripting when accepting data from text
boxes
Rasmus Lerdorf wrote:
> > hi i found it very helpful to know about hacks such as the below list
> > and was wondering if anyone had any more dumb mistakes they could tell
> > us before we make them.
> >
> > 1. http://www.somesite.com/source.php3?url=/etc/passwd
> > 2. http://www.somesite.com?page=../../../../etc/passwd
> > 3. not setting .inc files to be parsed by php
>
> This is the wrong solution to securing include files. The correct
> solution is to block any direct access to .inc files by either putting
> them outside your document root or by using an Apache deny rule.
>
> -Rasmus
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com