Re: Re: internals Digest 13 Apr 2012 01:23:19 -0000 Issue 2650
| From: | Yasuo Ohgaki | Date: | Sat, 14 Apr 2012 21:08:04 +0000 |
| Subject: | Re: Re: internals Digest 13 Apr 2012 01:23:19 -0000 Issue 2650 | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59935@lists.php.net to get a copy of this message | ||
Hi,
2012/4/15 Rasmus Schultz <rasmus@mindplay.dk>:
> the closing tag isn't even
> required to begin with, so you can really think of "<?php" as a 5-byte
> file-header.
If it is supposed to exist always at the beginning of files.
Anyway, file extension should not matter and it should be
a configuration as it is now. i.e. .phps for php source.
Current PHP is like C program without stack smashing/DEP
protection. Programmers should write correct codes always,
but they do make mistakes. The damage of LFI is extreme
and its possibility is common. There should be safer option or
protection provided by PHP.
One of the motivation of scripting use is safety. Safety comes from
memory management of it. Without memory management, there
should be much less code execution flaws. However, PHP is
ruining the advantage of scripting languages. IMHO.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net