Web Hosting Forum | Lunarpages
News: October 6, 2008 - Submit Your Site for the October 2008 Site of the Month!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
October 07, 2008, 03:53:50 PM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: HTML forms GET method  (Read 6816 times)
gruckiii
Spaceship Navigator
*****
Offline Offline

Posts: 93



WWW
« on: September 18, 2002, 12:30:00 AM »

i wrote a script to display the HTML code of some of my files       "[Smile]"      ... but now I want to make sure people can't use the script to look at any file on my page they want. I want to use the get method of passing information so I can make a link like
 http://www.gruckiii.com/ShowCode.php?path=WebLog.php

now the script forces "Files/" to be appended to the begining of the file name. So is this enough to keep people from looking at files in other directories? or is useing the GET method just a terrible idea here?

If it helps this is the code for my show file script
http://www.gruckiii.com/ShowCode.php?path=ShowCode.php

thats kind of ironic isn't it hehe     "[brows]"
 
 [ September 18, 2002, 08:31 AM: Message edited by: gruckiii ]
Logged
lethalweapon
Galactic Royalty
*****
Offline Offline

Posts: 242


WWW
« Reply #1 on: September 19, 2002, 04:56:00 PM »

Actually, no it doesn't.  If someone wanted to see perhaps the search.cgi code which is located in the http://www.gruckiii.com/search/ directory, all they would have to do is say: http://www.gruckiii.com/ShowCode.php?path=../search/search.cgi.

I just tested it out on your website and so what I said above is not just a guess.
Logged
gruckiii
Spaceship Navigator
*****
Offline Offline

Posts: 93



WWW
« Reply #2 on: September 19, 2002, 05:56:00 AM »

ok so this is obviously not safe hehe

I will have to rethink how to do this:)
Thanks for your help.

*Edit
I made a cheap fix to the script where I replace any ".."s with a $
Maybe I should not use GET? it would be kind of hard to do this with the POST method though.
 
 [ September 19, 2002, 02:12 PM: Message edited by: gruckiii ]
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM