Re: [RFC] [FINAL DISCUSSION] Script only include/require

From: Date: Sat, 21 Feb 2015 09:52:07 +0000
Subject: Re: [RFC] [FINAL DISCUSSION] Script only include/require
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-83384@lists.php.net to get a copy of this message
Hi Padraic, On Sat, Feb 21, 2015 at 5:18 PM, Pádraic Brady <padraic.brady@gmail.com> wrote: > Does this have any impact on allow_url_include or has that setting > been retained? > > Yes, folk do indeed try to do this, for example hitting up Google: > > > http://www.quora.com/Why-do-include-and-require_once-not-work-with-remote-files > allow_url_include=Off is kept. Attacker can easily place *.php files on remote servers. I guess PHP also allows php://input without it, doesn't it? php://input allows script execution via post. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#83384) next »