note 20858 deleted from features.remote-files by nlopess
| From: | nlopess@php.net | Date: | Wed, 16 Mar 2005 15:14:38 +0000 |
| Subject: | note 20858 deleted from features.remote-files by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-86553@lists.php.net to get a copy of this message | ||
Note Submitter: toby at butzon dot com
----
It's important to understand that remote files included/required into your script are NOT run
on your server (as previous posts have suggested).
Think about it this way: When I do this:
<?php include('http://www.example.com/some-include.php');
?>
..I'm actually asking PHP to make a separate HTTP request (just as your Web browser would) to
www.example.com. So, point your browser to that location. Do you see any PHP code? No. You will only
see HTML/text content.
(On the off chance that .php wasn't associated with the PHP module/binary, the code would only
be displayed. Thus, you would have to TRY to make a dangerous include scenario -- such as
eval()'ing a remoted included file specified by the user.)
Therefore, although this code may be vulnerable to an "untrustworthy information" attack
(where the information displayed by your Web site isn't actually information you endorse, even
though the information is ultimately transferred from your Web server), you are NOT vulnerable to
malicious access to your Web server resources, even if visitors can specify any remote server/file
that they please.