3 ms·
I tried it with the WordPress rewrites ( http://codex.wordpress.org/Using_Permalinks http://codex.wordpress.org/Using_Permalinks ) and I couldn't get it to work
by pierrefar 16y ago
I tried it with the WordPress rewrites ( http://codex.wordpress.org/Using_Permalinks http://codex.wordpress.org/Using_Permalinks ) and I couldn't get it to work. I think the problem is that I didn't know what to put in REQUEST_FILENAME. I tried the following:
REQUEST_FILENAME: I tried blank, "year/month/day/post-name" and "/year/month/day/post-name".
URL: year/month/day/post-name (to give hostname/year/month/day/post-name).
Rewrite rules copied from the WP link above:
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
I got one no match and two rules skipped.
EDIT: You have an XSS vulnerability in the URL field. Use the first test from this list: http://ha.ckers.org/xss.html http://ha.ckers.org/xss.html .
- mmelin 16y agoThanks! I've realized I need to come up with a better way to handle the special RewriteCond patterns, such as -f and -d. Right now all variables are handled in the same naive way, i.e. you get to specify their value in text form, but for things like -f/d/l that doesn't work (because for instance -f tests if the input string is a file in the current directory)
- nbpoole 16y agoThe RewriteRules are also vulnerable to XSS. Try entering RewriteRule . /index.php<script>alert(document.location)</script> [L] and submitting a URL.