Re: Security with include() function
| From: | Richard Lynch | Date: | Sat, 22 Sep 2001 03:13:47 +0000 |
| Subject: | Re: Security with include() function | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-68258@lists.php.net to get a copy of this message | ||
I think it is not parsed on the remote server, but is on the local server,
but they can't get the source from include().
That said, either way, if they can include() it, then can fopen/fread it, so
it really doesn't mattter....
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm
----- Original Message -----
From: Sed <sed@sed.is>
Newsgroups: php.general
To: <php-general@lists.php.net>
Sent: Thursday, September 20, 2001 1:16 PM
Subject: Security with include() function
> Hi,
>
> I was wandering if someone includes php-file with passwords, private
> paths etc. on a different server like this:
>
> include ("http://someserver/file.php");
>
> Will this same person be able to echo all the variables in that file.php
> script? Or is it in each and every time processed via php.exe before
> delivered?
>
> Thanks!
> SED
>
>
>