|
Posted by Nicholas Sherlock on 02/15/06 01:20
Richard Levasseur wrote:
> Please note that include() does not reset or otherwise prevent the
> limit on script execution from being enforced (other things can: system
> calls, sleep, etc, but include itself is not one of them).
>
> Aside: Including and executing unknown data would open up a potentially
> serious security vulnerability. That would be a Bad Thing (tm).
To be clear here, I'm serving user uploaded binary files, so Include()
would indeed be the kiss of death for my whole website.
Cheers,
Nicholas Sherlock
[Back to original message]
|