Re: allow_url_fopen should be INI_ALL
| From: | Russell Nelson | Date: | Wed, 29 Jun 2005 05:50:59 +0000 |
| Subject: | Re: allow_url_fopen should be INI_ALL | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-16989@lists.php.net to get a copy of this message | ||
Olivier Hill writes:
> Are you suggesting that someone could wipe out your entire machine by
> passing a remote script that would system('rm -rf /');?
It would "only" delete every file owned by the user that the webserver
runs as. On my server, that's 1846 files, some of which I'm fairly
attached to.
> There is no problems with the include() statement. The only thing
> missing, is a <blink> tag in the docs ;)
If there were no problems, then why would a <blink> tag be needed?
--
--My blog is at blog.russnelson.com | If you want to find
Crynwr sells support for free software | PGPok | injustice in economic
521 Pleasant Valley Rd. | +1 315-323-1241 | affairs, look for the
Potsdam, NY 13676-3213 | | hand of a legislator.