note 31446 added to function.include

From: Date: Tue, 22 Apr 2003 14:29:35 +0000
Subject: note 31446 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-46930@lists.php.net to get a copy of this message
You may think its secure to set an include base before dynamic include file. but its not sufficient. try this index.php?file=../../../etc/passwd so use this function instead include($file) if $file come from user. <? function secure_include($file) { $include_base="/home/includes/"; $file=str_replace("../","",$file); $file=str_replace("..","",$file); $file=str_replace("//","/",$file); if(file_exists($include_base.$file)) { include_once($include_base.$file); } } //SECURE USER INCLUDE secure_include($_REQUEST["file"]); ?> NOTE: you must use the same tips for fopen(), file()... use with user path. -- http://www.php.net/manual/en/function.include.php http://master.php.net/manage/user-notes.php?action=edit+31446 http://master.php.net/manage/user-notes.php?action=delete+31446 http://master.php.net/manage/user-notes.php?action=reject+31446

« previous php.notes (#46930) next »