#20599 [WFx->Opn]: DoS PHP/include...
| From: | sc2 at gmx dot at | Date: | Sat, 23 Nov 2002 20:00:18 +0000 |
| Subject: | #20599 [WFx->Opn]: DoS PHP/include... | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-25661@lists.php.net to get a copy of this message | ||
ID: 20599
User updated by: sc2@gmx.at
Reported By: sc2@gmx.at
-Status: Won't fix
+Status: Open
Bug Type: Scripting Engine problem
Operating System: suse
PHP Version: 4.2.3
New Comment:
yes thats not but it is a "php" releated problem..
i know it is free etc...
but if anyone of the PHP has the time / ressource...
/ knowledge... it doesnt hurt for php team..if they made a feature for
the admins of php..
it is the time,money or just a "presdige"?
be cool, dont be so "aggressiv" in your answers
Previous Comments:
------------------------------------------------------------------------
[2002-11-23 13:53:52] derick@php.net
It's really not for PHP to solve all problems of the world.
------------------------------------------------------------------------
[2002-11-23 13:51:35] sc2@gmx.at
ok thanks and sorry for your time
but where is responsible for this?...may a contact apache ..? for
hosters it would be easy when apache or php checks if in XX-Times the
same include is open....auto detect...(yes other ways works too but
oftens includes are used (with false scripts etc))
------------------------------------------------------------------------
[2002-11-23 13:36:53] sniper@php.net
This has been told many times before..you really should have searched
the bug database first.
If you didn't know, you can do the same thing in quite many
ways, not only with include()..
------------------------------------------------------------------------
[2002-11-23 13:36:31] derick@php.net
no, we're not going to disallow include/require.
Derick
------------------------------------------------------------------------
[2002-11-23 13:34:03] sc2@gmx.at
hello
i just wanna know if it is in any future version of php any variant to
stop DoS / with Includes
see
http://geodsoft.com/opinion/PHP-DoSattacks.htm
so that users can make endless lopp with includes
yes i know i can disable the include dir./require..but is there any
other that i can make (or php team) so that DoS is not so easy..
thx
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=20599&edit=1