作者PHP5 (Powered by Zend Engine2)
看板PHP
标题Re: [分享] 显示ISP名称 (不安全)
时间Mon Aug 20 13:27:00 2007
※ 引述《DarkKiller (System hacked)》之铭言:
: 想太多,你的程式里面放个 system("rm -rf"); 不就爆炸了。
原PO说的是这个吧
Security warning:
Remote file may be processed at the remote server (depending on the
file extension and the fact if the remote server runs PHP or not)
but it still has to produce a valid PHP script because it will be
processed at the local server. If the file from the remote server
should be processed there and outputted only, readfile() is much
better function to use. Otherwise, special care should be taken to
secure the remote script to produce a valid and desired code.
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.112.245.58