link protector - php
Posted:
Sat Mar 24, 2012 7:51 am
by itmees
is it possible to make so that php scripts wont run when inserted in link protector? For example when i insert basic "hello world" php script -
http://php.about.com/od/learnphp/qt/hello_world.htmthen protected page shows "Hello, World!" and not inserted php code.
anyways, thanks for awesome script!
Re: link protector - php
Posted:
Sat Mar 24, 2012 8:46 pm
by SamEA
That should not happen and if what you are saying is true, then this is a serious security issue. Please send me the link to where DLP is located for further investigation.
Just for clarification, you're saying that when PHP code is inserted instead of web links, it executes the inserted php code before/when viewing the hidden link(s)?
Re: link protector - php
Posted:
Sun Mar 25, 2012 8:18 am
by itmees
SamEA wrote:Just for clarification, you're saying that when PHP code is inserted instead of web links, it executes the inserted php code before/when viewing the hidden link(s)?
yes
i'll send you PM with links
Re: link protector - php
Posted:
Sun Mar 25, 2012 2:22 pm
by SamEA
Indeed this seems to be a security issue. I will have to do some further testing on my server until I can be certainly sure about this. If it does exist, I will come up with a patch as soon as I'm nearby a PC, as I'm abroad and Internet is limited. I advise you to not to use this script with the public as of yet. Thank you.
Re: link protector - php
Posted:
Sun Mar 25, 2012 9:35 pm
by itmees
thanks, i'll be waiting for patch