Re: potential solution to user streams + allow_url_include=off

From: Date: Sat, 19 May 2007 09:42:39 +0000
Subject: Re: potential solution to user streams + allow_url_include=off
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-29547@lists.php.net to get a copy of this message
2007/5/18, Stanislav Malyshev <stas@zend.com>: Sane hosters do not rely on general-purpose language to provide security, they use OS and hardware designed for exactly that purpose. ;)
unfortunately hosters has to equilibrate security vs/usability for their customers.. so disaloowing 100% access to outside world is frecuently not possible. The issue with this remote url include thingy is that is hard to find a valid use case ..does anyone has a **real** one ? why it was introduced in the first place..?? no, Im not talking about crippling the language for security reasons as some may argue..my point is this "feature" in the reality causes far more harm than good and it has become one of the top ways to attack applications since it's introduction..my intention is only to make people think if the hassle of adding new ini directives (like allow_url_include) or functions is worth. maybe with PHP6 this issue can be addressed from it's roots instead of adding yet another workaround. my $2.

« previous php.internals (#29547) next »