// Make sure the request isn't escaping to another directory
if ((substr($file, 0, 1) == '.') || (strpos($file, '..') > 0) ||
(substr($file, 0, 1) == '/') || (strpos($file, '/') > 0)) {
//header('Location: er.html?status=hack');
echo("Hack attempt detected!");
die();
}