Re: hacks we should know about

From: Date: Fri, 17 Aug 2001 04:17:31 +0000
Subject: Re: hacks we should know about
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-63123@lists.php.net to get a copy of this message
rasmus, if password.inc is being parsed by php then how would you get the code??? won't it just be a blank page??? oh i thought up one more ... 4. checking for html tags and php scripting when accepting data from text boxes Rasmus Lerdorf wrote: > > hi i found it very helpful to know about hacks such as the below list > > and was wondering if anyone had any more dumb mistakes they could tell > > us before we make them. > > > > 1. http://www.somesite.com/source.php3?url=/etc/passwd > > 2. http://www.somesite.com?page=../../../../etc/passwd > > 3. not setting .inc files to be parsed by php > > This is the wrong solution to securing include files. The correct > solution is to block any direct access to .inc files by either putting > them outside your document root or by using an Apache deny rule. > > -Rasmus _________________________________________________________ Do You Yahoo!? Get your free @yahoo.com address at http://mail.yahoo.com

« previous php.general (#63123) next »