note 30092 deleted from function.file by irchtml
| From: | irchtml@php.net | Date: | Sun, 19 Dec 2004 09:49:45 +0000 |
| Subject: | note 30092 deleted from function.file by irchtml | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-82034@lists.php.net to get a copy of this message | ||
Note Submitter: Jack at soinsincere dot com
----
Because files opened via the filesystem (versus URL) aren't parsed by the server, they can be
useful for returning the source of a PHP script. If you wanted users to be able to view the actual
scripts used on your site, for instance, you might include something like this:
if ($_SERVER['QUERY_STRING']=='source') {
header('Content-Type: text/plain');
print implode('',file($_SERVER['SCRIPT_FILENAME']));
return;
}
However, this could potentially create a rather nasty security hole. You should never, under any
circumstances, return the source of a file on your server specified by user submitted data ($_POST,
$_GET, $_REQUEST, etc.)
Example of foul play: http://server.com/?source&file='/system_passwords.php'
That's got bad news written all over it.