Hi Johannes,
On Sat, Feb 15, 2014 at 8:53 AM, Johannes Schlüter
<[email protected]>wrote:
> On Sat, 2014-02-15 at 07:28 +0900, Yasuo Ohgaki wrote:
> > 3) the include was intended to be non-PHP data, and the attacker
> > substitutes PHP code of their choice
> > 4) the include was intended to be non-PHP data, and the attacker accesses
> > different non-PHP data already on server
>
> People using the wrong feature won't be fixed by adding yet another way
> to open a file.
I have an idea. Please wait for a new RFC.
Regards,
--
Yasuo Ohgaki
[email protected]