Re: Re: Disabling PHP tags by php.ini and CLI options

From: Date: Wed, 11 Apr 2012 04:48:06 +0000
Subject: Re: Re: Disabling PHP tags by php.ini and CLI options
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-59704@lists.php.net to get a copy of this message
Hi! > > https://wiki.php.net/rfc/nophptags?&#why_this_is_better_than_now I'm sorry, but I do not understand how your proposal prevents LFI. Let's say you had this file kill.php: <?php kill_kill_kill(); and you were afraid that somebody would write the code "include $_GET['foo'];" and pass kill.php as foo and kill your server. Now, you propose banning <?php tag. So, kill.php would look like this: kill_kill_kill(); and you still can include it with "include $_GET['foo'];" and get the same result. Where's the difference? -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ (408)454-6900 ext. 227

« previous php.internals (#59704) next »