note 41333 deleted from function.readfile by aidan

From: Date: Fri, 24 Sep 2004 01:28:06 +0000
Subject: note 41333 deleted from function.readfile by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-77280@lists.php.net to get a copy of this message
Note Submitter: kazan at iastate dot edu ---- Say you have a script that is just wrapping pages with a template - if it contains a readfile() call and someone gives in invalid data such as '/index.html' on a unix/unix-like machine (in this specific case it was a OSX server) readfile will say "This file is in /", basically it will tell you where the file is and whether it exists - so this could be theorectically used for probing a system. I have corrected my script to avoid this. However the fact that it behaves with way, and it's not documented that it does, is dangerous security wise. This was discovered by one of my coworkers (The server admin) while we are getting ready for a security audit - at a DOE Facility.

« previous php.notes (#77280) next »