On Sun, 26 Mar 2000 09:06:10 +0200 (MET DST), Bernie <[EMAIL PROTECTED]>
wrote:
> Glenn wrote:
>> Arachne is not the problem.
>> The problem is STUPID web page designers.
>> This is impossible........ http://www.streetteam.net/../../../pm5k.html
>> Or am I wrong? Can you go three directories BEFORE root???
> No, but Arachne could change it as you have done yourself.
>> This works fine....... http://www.streetteam.net/pm5k.html
But then Arachne would become even more "bloated".
Michael would need to run every URL through a "filter" to edit-out all ../
references which would result in taking the user "below root".
For example:
http://sitename.com/pages/testpage.htm could contain these 2 links.
"../images/1.gif" (correct)
"../../images/2.gif" (incorrect)
If Arachne removed all ../ references, neither image could be accessed.
But, let's say that the page designer was completely wrong on both of
these links and the images are not in http://sitename.com/images/1.gif
and 2.gif but are actually in http://sitename.com/pages/images/1.gif and
2.gif
Then removing all ../ references _will_ access the images.
IMHO, NO program coder should attempt to correct someone else's mistakes.
When we find that a page designer has made a mistake we should tell them
about it and hope that they are willing to correct it.
--
Glenn McCorkle [EMAIL PROTECTED] North Jackson, Ohio, USA
DOS prog. for QV cameras http://www.angelfire.com/id/glenndoom/qvplay.html
Other stuff http:[EMAIL PROTECTED]/
Arachne, The Web Browser for DOS
Open the 'DOOR' to the WWW. Keep the 'windows' closed.
http://arachne.browser.org/ http://arachne.cz/