in reply to Download, don't redirect.

Of course, it goes without saying that you should restrict the file/path if your program obtains the filename from the remote user, so that they can't request silly things like /../../../../etc/passwd

Replies are listed 'Best First'.
RE: RE: Download, don't redirect.
by BBQ (Curate) on May 01, 2000 at 11:37 UTC
    I usually do that sort of checking when I parse the query_string. It seems to be a bad habbit closing down security later down the line when you can do it right off the bat when you receive your data. Think something looks suspicious? Chop it off regardless of what you'll be doing later...
    $str =~ s/\.\.\///g;