Re: [PHP] multisession download

2006-02-08 Thread Shu Hung (Koala)
2006/2/4, Richard Lynch <[EMAIL PROTECTED]>: > Put the path of the file you want in the URL? Sorry, what do you mean by this? > And make *SURE* you do not let that turn into things like: > /etc/passwd I have control to that in my code to prevent this from happening ^^ More info here: > htt

Re: [PHP] multisession download

2006-02-03 Thread Richard Lynch
Put the path of the file you want in the URL? And make *SURE* you do not let that turn into things like: /etc/passwd More info here: http://phpsec.org On Fri, February 3, 2006 1:54 am, Shu Hung (Koala) wrote: > Hello, > > I have a little strange question. > > Let say if I have a file "/home/user

[PHP] multisession download

2006-02-02 Thread Shu Hung (Koala)
Hello, I have a little strange question. Let say if I have a file "/home/user/somefile.jpg" I wanted to output this file from script, I wrote a little script: filedata['filepath'], "rb"); while (!feof($handle)) { $buffer = fr