Re: allow_url_fopen should be INI_ALL
| From: | Sebastian Mendel | Date: | Wed, 29 Jun 2005 14:27:17 +0000 |
| Subject: | Re: allow_url_fopen should be INI_ALL | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-17003@lists.php.net to get a copy of this message | ||
Derrell.Lipman@UnwiredUniverse.com wrote:
> Jani Taskinen <sniper@iki.fi> writes:
>
>> Please troll, do you go away if I close my eyes?
>
> That's not fair. Russell is providing strong arguments and rebuttals for
> every point. You may not agree with his points, but what he's doing is not
> trolling. This discussion seems to have strong backing on both sides of the
> issue.
i agree full!
isnt it possible to add a check to the include*()/require*() statement
that checks the parameter for existence in the superglobal $_REQUEST
if the same value is found in $_REQUEST it could raise a WARNING, and
notice the user about this security-leak.
--
Sebastian Mendel
www.sebastianmendel.de
www.sf.net/projects/phpdatetime | www.sf.net/projects/phptimesheet