Re: regular expression

From: Date: Thu, 01 Nov 2001 15:02:02 +0000
Subject: Re: regular expression
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-73159@lists.php.net to get a copy of this message
hello, what about using realpath() or dirname() and basename()? http://www.php.net/manual/en/function.realpath.php IMHO, it's more precise way to secure your directory structure. ----- Original Message ----- From: "Christian Reiniger" <creinig@mayn.de> To: "Galkov Vladimir" <galkov@kraft-s.php.net>; <php-general@lists.php.net> Sent: Thursday, November 01, 2001 12:50 PM Subject: Re: [PHP] regular expression On Thursday 01 November 2001 10:39, Galkov Vladimir wrote: > Need to remove all "../" "/.." from user inputing string to prevent > him walking and creating files&directories where I don't whant see > them/him... > > The string: > > $path = > eregi_replace('([..]{2,})|([./]{2})|([../]{3,})|([/.]{2})|([/..]{3})', > '', $path); > > works good with any combinations ( ../../..qwert.txt => qwert.txt) > untill somth like "/../asd/../qwert.txt" will be entered ... > (/../asd/../qwert.txt => asdqwert.txt). > So the qwestion is how upgrade regular expression to remove all this > correctly (with all entered directory names but NOT assigned their > names to file name... Here's what I use (take out the parts useful to you): function FixSrcURI ($SrcURI) { // remove script name $SrcURI = preg_replace ('#^/*{{$ Page.Source }}/*#', '', $SrcURI); // remove potentially harmful parts $SrcURI = preg_replace ('#/?\.\./?#', '/', $SrcURI); $SrcURI = preg_replace ('#/\./#', '/', $SrcURI); $SrcURI = preg_replace ('#/\.$#', '/', $SrcURI); $SrcURI = preg_replace ('#/{2,}#', '/', $SrcURI); $SrcURI = preg_replace ('#^/#', '', $SrcURI); if (preg_match ('#(\A|/)\.#', $SrcURI) || preg_match ('#CVS#', $SrcURI)) { pbHTTP_404 (); } if ($SrcURI == '') { return array ($SrcURI, -1, 'src'); } else { $matches = array (); if (preg_match ('#^[^/]+$#', $SrcURI)) { return array ($SrcURI, '', $SrcURI); } elseif (preg_match ('#^(.*)/([^/]*)$#', $SrcURI, $matches)) { return array ($SrcURI, $matches [1], $matches [2]); } else { pbHTTP_404 (); return false; } } } -- Christian Reiniger LGDC Webmaster (http://lgdc.sunsite.dk/) /* you are not expected to understand this */ - from the UNIX V6 kernel source -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#73159) next »