Re: [PHP] allow_url_fopen & allow_url_include

2009-03-03 Thread Chris
allow_url_fopen is not a security issue - it only returns the code, it does not execute it. But yes you can use curl instead of relying on allow_url_fopen. Well, allow_url_fopen is really a security issue. A renowned programmer (http://hasin.wordpress.com) said it could even cau

Re: [PHP] allow_url_fopen & allow_url_include

2009-03-03 Thread 9el
--- Use FreeOpenSourceSoftwares, Stop piracy, Let the developers live. Get a Free CD of Ubuntu mailed to your door without any cost. Visit : www.ubuntu.com -- On

Re: [PHP] allow_url_fopen & allow_url_include

2009-03-03 Thread Chris
Kaushal Shriyan wrote: On Tue, Mar 3, 2009 at 12:21 PM, Kaushal Shriyan mailto:kaushalshri...@gmail.com>> wrote: On Tue, Mar 3, 2009 at 11:52 AM, Chris mailto:dmag...@gmail.com>> wrote: Kaushal Shriyan wrote: Hi, I have enabled allow_url_fopen & allow_url_

Re: [PHP] allow_url_fopen & allow_url_include

2009-03-02 Thread Kaushal Shriyan
On Tue, Mar 3, 2009 at 12:21 PM, Kaushal Shriyan wrote: > On Tue, Mar 3, 2009 at 11:52 AM, Chris wrote: > >> Kaushal Shriyan wrote: >> >>> Hi, >>> >>> I have enabled allow_url_fopen & allow_url_include in php.ini file. >>> is it a security issue ? >>> >> >> allow_url_fopen means you can fetch pag

Re: [PHP] allow_url_fopen & allow_url_include

2009-03-02 Thread Kaushal Shriyan
On Tue, Mar 3, 2009 at 11:52 AM, Chris wrote: > Kaushal Shriyan wrote: > >> Hi, >> >> I have enabled allow_url_fopen & allow_url_include in php.ini file. >> is it a security issue ? >> > > allow_url_fopen means you can fetch pages: > > $page = file_get_contents('http://www.example.com'); > > This

Re: [PHP] allow_url_fopen & allow_url_include

2009-03-02 Thread Chris
Kaushal Shriyan wrote: Hi, I have enabled allow_url_fopen & allow_url_include in php.ini file. is it a security issue ? allow_url_fopen means you can fetch pages: $page = file_get_contents('http://www.example.com'); This is ok to enable - all it does is fetch the page. It does not execute t

[PHP] allow_url_fopen & allow_url_include

2009-03-02 Thread Kaushal Shriyan
Hi, I have enabled allow_url_fopen & allow_url_include in php.ini file. is it a security issue ? please help me understand about its implications. Thanks and Regards Kaushal