Re: potential solution to user streams + allow_url_include=off

From: Date: Sat, 19 May 2007 01:13:47 +0000
Subject: Re: potential solution to user streams + allow_url_include=off
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-29530@lists.php.net to get a copy of this message
2007/5/18, Greg Beaver <greg@chiaraquartet.net>:
Hi, I think I have a solution that would allow user streams in PHP 6 and still satisfy paranoid hosters.
s/paranoid/sane/g
as it is still possible through fsockopen() and other methods to access the outside world.
with a "tiny" :) difference, remote connections fsockopen() and friends will not parse and interprate PHP code directly unless the user eval() it..:)
A firewall is the only way to truly prevent access to the outside world.
yes, agree, but the remote "include" feature just make unintentional mistakes easy, if you look real life code that uses the url_include thingy.. in the 99% they meant readfile() ..ohh but what about fopen + eval ? well in that case the user will **always** want to eval() **explicitely** and there is nothing that PHP can do to avoid that stupiduty..

« previous php.internals (#29530) next »