Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:59492 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 63338 invoked from network); 9 Apr 2012 10:22:32 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 9 Apr 2012 10:22:32 -0000 Authentication-Results: pb1.pair.com header.from=keisial@gmail.com; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=keisial@gmail.com; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain gmail.com designates 74.125.82.170 as permitted sender) X-PHP-List-Original-Sender: keisial@gmail.com X-Host-Fingerprint: 74.125.82.170 mail-we0-f170.google.com Received: from [74.125.82.170] ([74.125.82.170:36126] helo=mail-we0-f170.google.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 83/51-56433-768B28F4 for ; Mon, 09 Apr 2012 06:22:32 -0400 Received: by werh12 with SMTP id h12so2939385wer.29 for ; Mon, 09 Apr 2012 03:22:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=h9iJcWI5OX0KVItnGr0JryqMD/avjcVIpjgEXIFEY+E=; b=dRWefrJ8XfCDW3Rv0C9W2Xm6k/6Xf39eROJxmmnS6MSXJk/eev81xsxUrnYJKXB30i cBZa75BhJ5J2+vJcXFp6ztxPXRT8uSvITe3wZCG36BmR4Vtvq4CLJQE/dJEEXLy2Are1 Ddd7k70NnuZTuWQHo2NXV0Ob83Ail2m5Ojl3NoWoEvWtIxInrHngTfuOaXYh7vL903Sx 7BviqsgMbuWIPDwEuA2U5maNsrcXOnMza5LkVHz6tT4nALwJRsHHsP5c48o09XBeWWep 7hBFyWL0WkboPy36ReQArjgmIuydRpLvUMWydSOyMyXlRZbG1Y8uxIvqL8Cz7uJnr7Jn rb2A== Received: by 10.216.136.232 with SMTP id w82mr3721267wei.119.1333966949277; Mon, 09 Apr 2012 03:22:29 -0700 (PDT) Received: from [192.168.1.26] (132.Red-83-32-10.dynamicIP.rima-tde.net. [83.32.10.132]) by mx.google.com with ESMTPS id ca3sm20397577wib.6.2012.04.09.03.22.27 (version=SSLv3 cipher=OTHER); Mon, 09 Apr 2012 03:22:28 -0700 (PDT) Message-ID: <4F82B9A0.1010808@gmail.com> Date: Mon, 09 Apr 2012 12:27:44 +0200 User-Agent: Thunderbird MIME-Version: 1.0 To: Tom Boutell CC: PHP Developers Mailing List References: <4F80C739.2060404@gmail.com> <4F817DE1.3020608@gmail.com> <2AD65A37-E1D3-4663-B580-D18C78118387@punkave.com> In-Reply-To: <2AD65A37-E1D3-4663-B580-D18C78118387@punkave.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Subject: Re: [PHP-DEV] PHP class files without This is an attempt to protect people who have written inherently insecure code anyway. One should never do a dynamic require to any untrusted location, if ever at all, yes? > Obviously. But that include vulnerabilty seems a precondition to the scenario Yasuo tries to protect.