Re: regular expression
| From: | Papp Gyozo | Date: | Thu, 01 Nov 2001 15:02:02 +0000 |
| Subject: | Re: regular expression | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-73159@lists.php.net to get a copy of this message | ||
hello,
what about using realpath() or dirname() and basename()?
http://www.php.net/manual/en/function.realpath.php
IMHO, it's more precise way to secure your directory structure.
----- Original Message -----
From: "Christian Reiniger" <creinig@mayn.de>
To: "Galkov Vladimir" <galkov@kraft-s.php.net>; <php-general@lists.php.net>
Sent: Thursday, November 01, 2001 12:50 PM
Subject: Re: [PHP] regular expression
On Thursday 01 November 2001 10:39, Galkov Vladimir wrote:
> Need to remove all "../" "/.." from user inputing string to prevent
> him walking and creating files&directories where I don't whant see
> them/him...
>
> The string:
>
> $path =
> eregi_replace('([..]{2,})|([./]{2})|([../]{3,})|([/.]{2})|([/..]{3})',
> '', $path);
>
> works good with any combinations ( ../../..qwert.txt => qwert.txt)
> untill somth like "/../asd/../qwert.txt" will be entered ...
> (/../asd/../qwert.txt => asdqwert.txt).
> So the qwestion is how upgrade regular expression to remove all this
> correctly (with all entered directory names but NOT assigned their
> names to file name...
Here's what I use (take out the parts useful to you):
function FixSrcURI ($SrcURI)
{
// remove script name
$SrcURI = preg_replace ('#^/*{{$ Page.Source }}/*#', '', $SrcURI);
// remove potentially harmful parts
$SrcURI = preg_replace ('#/?\.\./?#', '/', $SrcURI);
$SrcURI = preg_replace ('#/\./#', '/', $SrcURI);
$SrcURI = preg_replace ('#/\.$#', '/', $SrcURI);
$SrcURI = preg_replace ('#/{2,}#', '/', $SrcURI);
$SrcURI = preg_replace ('#^/#', '', $SrcURI);
if (preg_match ('#(\A|/)\.#', $SrcURI) ||
preg_match ('#CVS#', $SrcURI))
{
pbHTTP_404 ();
}
if ($SrcURI == '') {
return array ($SrcURI, -1, 'src');
}
else {
$matches = array ();
if (preg_match ('#^[^/]+$#', $SrcURI))
{
return array ($SrcURI, '', $SrcURI);
}
elseif (preg_match ('#^(.*)/([^/]*)$#', $SrcURI, $matches))
{
return array ($SrcURI, $matches [1], $matches [2]);
}
else
{
pbHTTP_404 ();
return false;
}
}
}
--
Christian Reiniger
LGDC Webmaster (http://lgdc.sunsite.dk/)
/* you are not expected to understand this */
- from the UNIX V6 kernel source
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net