Re: PHP class files without <?php at the top
| From: | Ángel González | Date: | Mon, 09 Apr 2012 10:27:44 +0000 |
| Subject: | Re: PHP class files without <?php at the top | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59492@lists.php.net to get a copy of this message | ||
On 08/04/12 14:31, Tom Boutell wrote:
> This is an attempt to protect people who have written inherently insecure code anyway. One
> should never do a dynamic require to any untrusted location, if ever at all, yes?
>
Obviously. But that include vulnerabilty seems a precondition to the
scenario Yasuo tries to protect.