note 34285 modified in security.hiding by danbrown
| From: | danbrown@php.net | Date: | Tue, 28 Dec 2010 00:45:22 +0000 |
| Subject: | note 34285 modified in security.hiding by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-175259@lists.php.net to get a copy of this message | ||
More fun includes files without file extensions.
Simply add that ForceType application/x-httpd-php bit to an Apache .htaccess and you're set.
Oh yea, it gets even better when you play with stuff like the following:
<?php
substr($_SERVER['PATH_INFO'],1);
?>
e.g. www.example.com/somepage/55
And:
<?php
foreach ( explode('/',$_SERVER['PATH_INFO']) as $pair ) {
list($key,$value) = split('=',$pair,2);
$param[$key] = stripslashes($value);
}
?>
e.g. www.example.com/somepage/param1=value1/param2=value2/etc=etc
Enjoy =)
--was--
More fun includes files without file extensions.
Simply add that ForceType application/x-httpd-php bit to an Apache .htaccess and you're set.
Oh yea, it gets even better when you play with stuff like the following:
substr($_SERVER['PATH_INFO'],1);
e.g. www.yoursite.com/somepage/55
And:
foreach ( explode('/',$_SERVER['PATH_INFO']) as $pair ) {
list($key,$value) = split('=',$pair,2);
$param[$key] = stripslashes($value);
}
e.g. www.yoursite.com/somepage/param1=value1/param2=value2/etc=etc
Enjoy =)
http://php.net/manual/en/security.hiding.php