Re: Preload scripts and preloaded scripts only options

From: Date: Sat, 16 May 2015 21:06:54 +0000
Subject: Re: Preload scripts and preloaded scripts only options
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-86268@lists.php.net to get a copy of this message
Hi Johannes, On Sat, May 16, 2015 at 11:32 PM, Johannes Schlüter <johannes@schlueters.de> wrote: > That whitelist is called open_basedir. > http://php.net/manual/en/ini.core.php#ini.open-basedir > I'm trying to eliminate risks of script inclusion attack. open_basedir is not good enough to prevent include('/path/to/upload/attack_image_file.png'); Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#86268) next »