note 30092 added to function.file

From: Date: Thu, 06 Mar 2003 04:52:28 +0000
Subject: note 30092 added to function.file
Groups: php.notes 
Request: Send a blank email to php-notes+get-44918@lists.php.net to get a copy of this message
Because files opened via the filesystem (versus URL) aren't parsed by the server, they can be useful for returning the source of a PHP script. If you wanted users to be able to view the actual scripts used on your site, for instance, you might include something like this: if ($_SERVER['QUERY_STRING']=='source') { header('Content-Type: text/plain'); print implode('',file($_SERVER['SCRIPT_FILENAME'])); return; } However, this could potentially create a rather nasty security hole. You should never, under any circumstances, return the source of a file on your server specified by user submitted data ($_POST, $_GET, $_REQUEST, etc.) Example of foul play: http://server.com/?source&file='/system_passwords.php' That's got bad news written all over it. -- http://www.php.net/manual/en/function.file.php http://master.php.net/manage/user-notes.php?action=edit+30092 http://master.php.net/manage/user-notes.php?action=delete+30092 http://master.php.net/manage/user-notes.php?action=reject+30092

« previous php.notes (#44918) next »