note 42951 modified in function.count by danbrown

From: Date: Fri, 09 Jan 2009 23:02:00 +0000
Subject: note 42951 modified in function.count by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-149015@lists.php.net to get a copy of this message
I have found on upload scripts or on file manipulation scripts that people can trick a classic file type filter: example: <?php $filename="bob.jpg.wav"; $bits= explode(".",$filename); $extention= $bits[1]; if($extention == "jpg"){ echo"Not correct"; exit; } ?> This returns the filename extention as jpg not wav. One way to change this is to use count() : example: <?php $filename="bob.jpg.wav"; $bits= explode(".",$filename); $extention= $bits[count($bits) - 1]; if($extention == "jpg"){ echo "Not correct"; exit; } ?> This returns the filename extention as wav not jpg. --was-- I have found on upload scripts or on file manipulation scripts that people can trick a classic file type filter: example: <?php $filename="bob.jpg.wav"; $bits= explode(".",$filename); $extention= $bits[1]; if($extention == "jpg"){ echo"Not correct"; exit; } ?> This returns the filename extention as jpg not wav. One way to change this is to use count() : example: <?php $filename="bob.jpg.wav"; $bits= explode(".",$filename); $extention= $bits[count($bits) - 1]; if($extention == "jpg"){ echo"Not correct"; exit; } ?> This returns the filename extention as wav not jpg. http://php.net/manual/en/function.count.php

« previous php.notes (#149015) next »