note 20858 deleted from features.remote-files by nlopess

From: Date: Wed, 16 Mar 2005 15:14:38 +0000
Subject: note 20858 deleted from features.remote-files by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-86553@lists.php.net to get a copy of this message
Note Submitter: toby at butzon dot com ---- It's important to understand that remote files included/required into your script are NOT run on your server (as previous posts have suggested). Think about it this way: When I do this: <?php include('http://www.example.com/some-include.php'); ?> ..I'm actually asking PHP to make a separate HTTP request (just as your Web browser would) to www.example.com. So, point your browser to that location. Do you see any PHP code? No. You will only see HTML/text content. (On the off chance that .php wasn't associated with the PHP module/binary, the code would only be displayed. Thus, you would have to TRY to make a dangerous include scenario -- such as eval()'ing a remoted included file specified by the user.) Therefore, although this code may be vulnerable to an "untrustworthy information" attack (where the information displayed by your Web site isn't actually information you endorse, even though the information is ultimately transferred from your Web server), you are NOT vulnerable to malicious access to your Web server resources, even if visitors can specify any remote server/file that they please.

« previous php.notes (#86553) next »