Re: Re: Disabling PHP tags by php.ini and CLI options
| From: | Stas Malyshev | Date: | Wed, 11 Apr 2012 04:48:06 +0000 |
| Subject: | Re: Re: Disabling PHP tags by php.ini and CLI options | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59704@lists.php.net to get a copy of this message | ||
Hi!
>
> https://wiki.php.net/rfc/nophptags?&#why_this_is_better_than_now
I'm sorry, but I do not understand how your proposal prevents LFI. Let's
say you had this file kill.php:
<?php kill_kill_kill();
and you were afraid that somebody would write the code "include
$_GET['foo'];" and pass kill.php as foo and kill your server. Now, you
propose banning <?php tag. So, kill.php would look like this:
kill_kill_kill();
and you still can include it with "include $_GET['foo'];" and get the
same result. Where's the difference?
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227