Re: Preload scripts and preloaded scripts only options
| From: | Yasuo Ohgaki | Date: | Sat, 16 May 2015 21:06:54 +0000 |
| Subject: | Re: Preload scripts and preloaded scripts only options | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-86268@lists.php.net to get a copy of this message | ||
Hi Johannes,
On Sat, May 16, 2015 at 11:32 PM, Johannes Schlüter <johannes@schlueters.de>
wrote:
> That whitelist is called open_basedir.
> http://php.net/manual/en/ini.core.php#ini.open-basedir
>
I'm trying to eliminate risks of script inclusion attack. open_basedir is
not good enough to
prevent
include('/path/to/upload/attack_image_file.png');
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net