note 41333 added to function.readfile

From: Date: Tue, 06 Apr 2004 16:31:23 +0000
Subject: note 41333 added to function.readfile
Groups: php.notes 
Request: Send a blank email to php-notes+get-67723@lists.php.net to get a copy of this message
Say you have a script that is just wrapping pages with a template - if it contains a readfile() call and someone gives in invalid data such as '/index.html' on a unix/unix-like machine (in this specific case it was a OSX server) readfile will say "This file is in /", basically it will tell you where the file is and whether it exists - so this could be theorectically used for probing a system. I have corrected my script to avoid this. However the fact that it behaves with way, and it's not documented that it does, is dangerous security wise. This was discovered by one of my coworkers (The server admin) while we are getting ready for a security audit - at a DOE Facility. ---- Manual Page -- http://www.php.net/manual/en/function.readfile.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+41333 Delete -- http://master.php.net/manage/user-notes.php?action=delete+41333&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+41333&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#67723) next »