Re: Re: [RFC] No PHP tags
| From: | Yasuo Ohgaki | Date: | Wed, 12 Feb 2014 02:16:20 +0000 |
| Subject: | Re: Re: [RFC] No PHP tags | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72491@lists.php.net to get a copy of this message | ||
Hi Rasmus,
On Wed, Feb 12, 2014 at 10:29 AM, Rasmus Lerdorf <rasmus@lerdorf.com> wrote:
> On 2/11/14, 3:33 PM, Yasuo Ohgaki wrote:
> > I forgot to mention 2nd. I usually disable engine for upload directory
> > by httpd.conf
> > or do not allow to upload anything under webroot.
>
> Right, you don't put your upload dir under your webroot. Even with php
> disabled, you wouldn't want your upload dir in your web root since the
> bad guys could upload nasty javascript or other interesting things and
> xss/csrf your users through that.
>
> As for LFI, I usually just set my open_basedir to the directories I know
> my application will access files from. So even if I make a mistake
> somewhere, the bad guys won't be able to trick any of my includes into
> including any other files. This seems like a much simpler and more
> effective way to combat LFI than introducing a template mode.
I agree completely .
Sorry that the RFC was hard to read. I reorganized the RFC.
script() and script_once() will solve most of LFI issue. I added
"Open Issue" section. I think all we have to consider is whether
we allow a little inconsistency for directly called scripts or not.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net