note 31182 added to security.filesystem

From: Date: Sat, 12 Apr 2003 09:33:36 +0000
Subject: note 31182 added to security.filesystem
Groups: php.notes 
Request: Send a blank email to php-notes+get-46537@lists.php.net to get a copy of this message
A way to validate if a requested directory or file (passed by argument or what-have-you) is in your doc root tree: $t = apache_lookup_uri($dir); if ( (!file_exists($t->filename)) || (is_null($dir)) ) { echo "NOT VALID!"; } else { echo "VALID -- " . $t->filename; } This prevents the user from passing in an empty dir (simply remove the is_null() to eliminate this feature). Further security is up to the programmer (At least this way you can throw out a chunk of ../../../../../etc/passwd). -- http://www.php.net/manual/en/security.filesystem.php http://master.php.net/manage/user-notes.php?action=edit+31182 http://master.php.net/manage/user-notes.php?action=delete+31182 http://master.php.net/manage/user-notes.php?action=reject+31182

« previous php.notes (#46537) next »