4 ms·
Ah yes, you're right. Totally mis-read the code. It'd still leave access to any files in the same (or sub) directory starting with http, which realistically wo
by philo23 10y ago
Ah yes, you're right. Totally mis-read the code.
It'd still leave access to any files in the same (or sub) directory starting with http, which realistically would probably be none but still something to bear in mind.
- nitrogen 10y agoRight, best to check the whole URL. Something like "http/../../../etc/passwd" might get through otherwise.
- milankragujevic 10y agoLike.... $url = rawurldecode($_GET['url']); $url_without_protocol = str_replace(array('https://', 'http://'), '', $url); $protocol = (stristr($url, 'https://') ? 'https' : 'http'); $page = file_get_contents($protocol . '://' . $url_without_protocol);
- kh_hk 10y agoWhat about u = urlparse(url) if u.scheme not in ['http', 'https']: return 400