Re: [RFC] [FINAL DISCUSSION] Script only include/require
| From: | Yasuo Ohgaki | Date: | Sat, 21 Feb 2015 09:52:07 +0000 |
| Subject: | Re: [RFC] [FINAL DISCUSSION] Script only include/require | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-83384@lists.php.net to get a copy of this message | ||
Hi Padraic,
On Sat, Feb 21, 2015 at 5:18 PM, Pádraic Brady <padraic.brady@gmail.com>
wrote:
> Does this have any impact on allow_url_include or has that setting
> been retained?
>
> Yes, folk do indeed try to do this, for example hitting up Google:
>
>
> http://www.quora.com/Why-do-include-and-require_once-not-work-with-remote-files
>
allow_url_include=Off is kept.
Attacker can easily place *.php files on remote servers.
I guess PHP also allows php://input without it, doesn't it?
php://input allows script execution via post.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net