Re: UPDATED RFC version 1.1: source files without opening <?php tag

From: Date: Wed, 11 Apr 2012 23:51:57 +0000
Subject: Re: UPDATED RFC version 1.1: source files without opening <?php tag
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-59767@lists.php.net to get a copy of this message
Hello, On Wed, Apr 11, 2012 at 4:42 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > > Making sure how it behaves. > include $_GET['filename']; > gave free pass to system, right? > > Regards, > Why on earth do you insist on continually posting that horrid snippet of code lol? I can't help but to laugh and suspect that at this point you are trolling.. In case you are being serious, "include $_GET['filename'];" is _HORRIBLE_. It's _WRONG_. No one should do it. _EVER_. For any reason. If a developer is wise enough to use your corner case proposed fix to circumvent the "attack type" (aka developer negligence), he is wise enough to come up with a CORRECT solution. -Chris

« previous php.internals (#59767) next »