top | item 40492231

(no title)

kennydude | 1 year ago

Might be a little naive but this looks to be mostly exploited by blindly trusting user input which pretty much always should be avoided

discuss

order

arp242|1 year ago

Yes, but people make mistakes, and escalating that to 100 and an RCE is not brilliant.

There really should be an option to just these stupid fopen wrappers. The entire feature is profoundly misguided, and not even that useful.

The post says "Big applications (such as Drupal or Magento) have been disabling the phar:// protocol", but I can't even figure out how to do that in a quick check, other than a configure option.