Re: include statement
| From: | Alexander Wagner | Date: | Wed, 17 Jan 2001 17:04:49 +0000 |
| Subject: | Re: include statement | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-35076@lists.php.net to get a copy of this message | ||
Michael Zornek wrote:
> which is scary cause this worked too:
>
> <?PHP
> include("/usr/local/apache/conf/httpd.conf");
> ?>
>
> doesn't this seem like a huge security hole?
No. If you know can trust your scripts, this is possible, but trusted scripts
won't do any abuse, will they?
If you can't trust your scripts, use safe-mode, and it isn't possible any
more.
Wagner
--
One maniac alone can do what 20 together cannot