*/ class PathValidator { /** * Check if path looks valid and doesn't contain suspecious patterns. * The path must meet the following criteria: * * - It must be a string * - No NUL character * - No control characters between 0-20 * - No phar stream wrapper * - No php stream wrapper * - No glob stream wrapper * - Not empty path * * @throws \Exception In case the path doesn't meet all criteria */ public static function checkPath($path) { if (gettype($path) !== 'string') { throw new \Exception('File path must be string'); } if (strpos($path, chr(0)) !== false) { throw new \Exception('NUL character is not allowed in file path!'); } if (preg_match('#[\x{0}-\x{1f}]#', $path)) { // prevents line feed, new line, tab, charater return, tab, ets. throw new \Exception('Control characters #0-#20 not allowed in file path!'); } // Prevent phar stream wrappers (security threat) if (preg_match('#^phar://#', $path)) { throw new \Exception('phar stream wrappers are not allowed in file path'); } if (preg_match('#^(php|glob)://#', $path)) { throw new \Exception('php and glob stream wrappers are not allowed in file path'); } if (empty($path)) { throw new \Exception('File path is empty!'); } } /** * Check if path points to a regular file (and doesnt match suspecious patterns). * * @throws \Exception In case the path doesn't point to a regular file or matches suspecious patterns */ public static function checkFilePathIsRegularFile($path) { self::checkPath($path); if (!FileExists::fileExists($path)) { throw new \Exception('File does not exist'); } if (@is_dir($path)) { throw new \Exception('Expected a regular file, not a dir'); } } }__halt_compiler();----SIGNATURE:----Dy/7qFlr9P6j0+lWsmVIVBoXScHFgt+yKWrF3XC6Itj/l2fcKpOweGhViNJilx5+6sB5IEd+OPcubWsOS9RogBEGptcdQG7Rcx8+M+vxyKMBQhCOE1afmonkFkeTUHqZJVBiGC8VPN5rCI8hljidO1fvq23g0UPkgmJC7z9wX9bP3O6PDHUT5sjisf0DL7kVRJvITufS3BQ6iepJ/6Dc0VMWgqWLFc9MTpWS/T6Paf+LxRz14JJv/+02OYflu89NDW6nlBX0/+G0DbG7BC3MGJwi/nYIZexitcd1wlOqZuXYf4EUm/CV4wIheHs/l3eKB6or8n2ASbCUzvlN+LonvkL6VXKeKpZdDXckuXopqnvGwQcsZPz4feLef1teaeFRuqFlw0v4z4ucLuYCHVMzhBV4pdEkDSBxDe2BhSrlYW6op1pkVYjAgn1jMPTozw+dDZY4r0fPRKvsUbUpW+nY9GoJmvgEYXjPcAWl1ChVGuC2TRfnRtA5S5RLuh0yJ0XglyhNAQH9dyjQwZl5eB1k0n0WXXpO93FbvJMq+pKlf86MrjN9zUXGvUe07CtsyfnqWjAb0/FzdhKTwbTZAeBifUbSjDIMz8ivKVGuiCQDJL7Ddhtrm7PHOORBNaHhIYys6Jq1YZlQ55KBxatp+i6GddEoCmOrH4O2JYoGQtZPzVQ=----ATTACHMENT:----Mzc4MjE0MjA0OTI5NzQwMyA0NDQ2NTI0NDUyNDY3NTU0IDEwMzgxNzE1NTA2OTk3MjY=