Sane path? Avoiding people climbing in directory structure ../../
| From: | Jimmy Lantz | Date: | Mon, 20 May 2002 21:15:04 +0000 |
| Subject: | Sane path? Avoiding people climbing in directory structure ../../ | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-98532@lists.php.net to get a copy of this message | ||
Hi,
I'm planning on using userinput as a part of path to read (horrific I know :)
So to make this userinput a bit more secure I'm thinking to use
$path = escapeshellarg($path);
$path = str_replace("../","",$path);
I'm thinking to use a basedir in a constant something like /usr/home/userdir (this also being set in php.ini)
then add the userinput and then append that to the constant and then use opendir() on it.
I want to avoid people putting in nice little strings like ../../../etc/
Any other pointers?
/ Jim
Security is a state of mind not a sales arguement!
*** Secret behind flying=
Throw yourself at the ground and miss :-)