Re: [PHP-INST] Malicious code allows people to browse thru /

2002-10-08 Thread Chris Hewitt
Thiago Vinhas wrote: >if not, PHP Developers must find a way to stop this. THe following code >allows someone to browse the entire directory three of a server. > You (or someone on your shared server, if you share it) would have to put this code onto it in order for it to happen. Yes there are

Re: [PHP-INST] Malicious code allows people to browse thru /

2002-10-08 Thread Jeffrey_N_Dyke
cc: Subject: [PHP-INST] Malicious code allows people to browse thru

Re: [PHP-INST] Malicious code allows people to browse thru /

2002-10-08 Thread Steve Cayford
...and? It's a programming language. If you want to program a file browser into your website why should PHP try to stop you? -Steve On Tuesday, October 8, 2002, at 12:31 PM, Thiago Vinhas wrote: > > Hi. I found something that is really dangerous. I hope there is a > configuration variable on

[PHP-INST] Malicious code allows people to browse thru /

2002-10-08 Thread Thiago Vinhas
Hi. I found something that is really dangerous. I hope there is a configuration variable on php.ini that denies what this script do, but if not, PHP Developers must find a way to stop this. THe following code allows someone to browse the entire directory three of a server. Here is the code: $d