note 31182 deleted from security.filesystem by nlopess
| From: | nlopess@php.net | Date: | Tue, 13 Jan 2004 15:23:50 +0000 |
| Subject: | note 31182 deleted from security.filesystem by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-63449@lists.php.net to get a copy of this message | ||
Note Submitter: lisa at rochester isp
----
A way to validate if a requested directory or file (passed by argument or what-have-you) is in your
doc root tree:
$t = apache_lookup_uri($dir);
if ( (!file_exists($t->filename)) || (is_null($dir)) ) {
echo "NOT VALID!";
}
else {
echo "VALID -- " . $t->filename;
}
This prevents the user from passing in an empty dir (simply remove the is_null() to eliminate this
feature). Further security is up to the programmer (At least this way you can throw out a chunk of
../../../../../etc/passwd).