Re: Re: [RFC] No PHP tags

From: Date: Wed, 12 Feb 2014 02:16:20 +0000
Subject: Re: Re: [RFC] No PHP tags
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-72491@lists.php.net to get a copy of this message
Hi Rasmus, On Wed, Feb 12, 2014 at 10:29 AM, Rasmus Lerdorf <rasmus@lerdorf.com> wrote: > On 2/11/14, 3:33 PM, Yasuo Ohgaki wrote: > > I forgot to mention 2nd. I usually disable engine for upload directory > > by httpd.conf > > or do not allow to upload anything under webroot. > > Right, you don't put your upload dir under your webroot. Even with php > disabled, you wouldn't want your upload dir in your web root since the > bad guys could upload nasty javascript or other interesting things and > xss/csrf your users through that. > > As for LFI, I usually just set my open_basedir to the directories I know > my application will access files from. So even if I make a mistake > somewhere, the bad guys won't be able to trick any of my includes into > including any other files. This seems like a much simpler and more > effective way to combat LFI than introducing a template mode. I agree completely . Sorry that the RFC was hard to read. I reorganized the RFC. script() and script_once() will solve most of LFI issue. I added "Open Issue" section. I think all we have to consider is whether we allow a little inconsistency for directly called scripts or not. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#72491) next »