note 30092 added to function.file
| From: | Jack at soinsincere dot com | Date: | Thu, 06 Mar 2003 04:52:28 +0000 |
| Subject: | note 30092 added to function.file | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-44918@lists.php.net to get a copy of this message | ||
Because files opened via the filesystem (versus URL) aren't parsed by the server, they can be
useful for returning the source of a PHP script. If you wanted users to be able to view the actual
scripts used on your site, for instance, you might include something like this:
if ($_SERVER['QUERY_STRING']=='source') {
header('Content-Type: text/plain');
print implode('',file($_SERVER['SCRIPT_FILENAME']));
return;
}
However, this could potentially create a rather nasty security hole. You should never, under any
circumstances, return the source of a file on your server specified by user submitted data ($_POST,
$_GET, $_REQUEST, etc.)
Example of foul play: http://server.com/?source&file='/system_passwords.php'
That's got bad news written all over it.
--
http://www.php.net/manual/en/function.file.php
http://master.php.net/manage/user-notes.php?action=edit+30092
http://master.php.net/manage/user-notes.php?action=delete+30092
http://master.php.net/manage/user-notes.php?action=reject+30092