note 30092 deleted from function.file by irchtml

From: Date: Sun, 19 Dec 2004 09:49:45 +0000
Subject: note 30092 deleted from function.file by irchtml
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-82034@lists.php.net to get a copy of this message
Note Submitter: Jack at soinsincere dot com ---- Because files opened via the filesystem (versus URL) aren't parsed by the server, they can be useful for returning the source of a PHP script. If you wanted users to be able to view the actual scripts used on your site, for instance, you might include something like this: if ($_SERVER['QUERY_STRING']=='source') { header('Content-Type: text/plain'); print implode('',file($_SERVER['SCRIPT_FILENAME'])); return; } However, this could potentially create a rather nasty security hole. You should never, under any circumstances, return the source of a file on your server specified by user submitted data ($_POST, $_GET, $_REQUEST, etc.) Example of foul play: http://server.com/?source&file='/system_passwords.php' That's got bad news written all over it.

« previous php.notes (#82034) next »