Re: PHP class files without <?php at the top
| From: | Ángel González | Date: | Mon, 09 Apr 2012 20:11:18 +0000 |
| Subject: | Re: PHP class files without <?php at the top | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59540@lists.php.net to get a copy of this message | ||
On 09/04/12 21:17, Yasuo Ohgaki wrote:
> Please do not tell me that programmer should
> learn not to, since it's not a protection but education.
Hire a more competent programmer? If he writes such code,
he will be completely unaware of the subtleties of XSS, or how
SQL should be escaped, and his code is probably beyond
"protection". You're better served by rewriting it.
> If programmers/administrators could disable embed mode,
> then systems will be protected from vulnerable codes.
How do you enforce that the application you need doesn't rely on it?
Note: 'education' is also forbidden as you restricted it in the
previous question. :-)