Re: UPDATED RFC version 1.1: source files without opening <?php tag
| From: | Chris Stockton | Date: | Wed, 11 Apr 2012 23:51:57 +0000 |
| Subject: | Re: UPDATED RFC version 1.1: source files without opening <?php tag | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59767@lists.php.net to get a copy of this message | ||
Hello,
On Wed, Apr 11, 2012 at 4:42 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
>
> Making sure how it behaves.
> include $_GET['filename'];
> gave free pass to system, right?
>
> Regards,
>
Why on earth do you insist on continually posting that horrid snippet
of code lol? I can't help but to laugh and suspect that at this point
you are trolling.. In case you are being serious, "include
$_GET['filename'];" is _HORRIBLE_. It's _WRONG_. No one should do it.
_EVER_. For any reason. If a developer is wise enough to use your
corner case proposed fix to circumvent the "attack type" (aka
developer negligence), he is wise enough to come up with a CORRECT
solution.
-Chris