Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-19-2011, 09:42 AM   #1
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
php include() alternative?

hi

i want to include a file (it's just a bit of javascript) from domainA into a php page on domainB (all on the same server). to do this i have to have allow_url_include = on in my php.ini which i believe is a big security risk. has anyone got any alternative solutions that are safer,?

the include is just so i can test various popups over 100's of sites by just changing the javacript in the one file. so i would be grateful for any other simple solutions too.

thanks in advance
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:43 AM   #2
stocktrader23
Let's do some business.
 
stocktrader23's Avatar
 
Industry Role:
Join Date: Jan 2003
Location: The dirty south.
Posts: 18,781
iframes?
__________________


Hands Free Adult - Join Once, Earn For Life

"I try to make a habit of bouncing my eyes up to the face of a beautiful woman, and often repeat “not mine” in my head or even verbally. She’s not mine. God has her set aside. She’s not mine. She’s His little girl, and she needs me to fight for her by keeping my eyes where they should be."
stocktrader23 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:45 AM   #3
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
Why are you including it with php? just use a script tag with src='xxxxx'...
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:46 AM   #4
Avalana
Confirmed User
 
Avalana's Avatar
 
Industry Role:
Join Date: Jun 2011
Location: Coconut Grove
Posts: 594
Not sure about: require_once();
__________________
bad behavior - Adult & Porn Site Reviews - Need a honest Review for your Adult Porn Site? Just drop me a line - ICQ @BADBEHAVIOR or SKYPE avalana.porngeekz
Avalana is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:49 AM   #5
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
Quote:
Originally Posted by woj View Post
Why are you including it with php? just use a script tag with src='xxxxx'...
because the the bit of code i am calling is a javascript with src="xxx" as well and i'm assuming you can't nest it?
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:50 AM   #6
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
Quote:
Originally Posted by roly View Post
because the the bit of code i am calling is a javascript with src="xxx" as well and i'm assuming you can't nest it?
you probably can but hard to really say without knowing exactly what you are trying to do...
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:52 AM   #7
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
using curl?
Code:
$ch = curl_init();
curl_setopt ($ch, CURLOPT_URL, 'http://www.domainA.com/');
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
$contents = curl_exec($ch);
curl_close($ch);
echo $contents;
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:52 AM   #8
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
Quote:
Originally Posted by stocktrader23 View Post
iframes?
no that doesn't seem to work
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:54 AM   #9
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
You want to include the server path to the file, not the URL. So something like:
include ('../../othersite.com/public_html/stuff.inc');

Symlinks on the server can simplify that.
If suexec is preventing you from doing the include, suexec a more serious security hole than fopen_url, as bad as fopen_url is.


The above is if you have to include() instead of doing:

script type="text/javascript" src="http://somesite.com/cool.js"
__________________
For historical display only. This information is not current:
support&#64;bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:57 AM   #10
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
Quote:
Originally Posted by roly View Post
allow_url_include = on in my php.ini which i believe is a big security risk.
mostly a huge waste of resources if both sites are on the same server.

Quote:
the include is just so i can test various popups over 100's of sites by just changing the javacript in the one file.
1. use readfile() instead of include() as the contents of the file won't need to be parsed for php code.
2. readfile("/full/path/to/whereever/u/put/thefile/file.js");
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 09:59 AM   #11
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
Quote:
Originally Posted by raymor View Post
You want to include the server path to the file, not the URL. So something like:
include ('../../othersite.com/public_html/stuff.inc');

Symlinks on the server can simplify that.
If suexec is preventing you from doing the include, suexec a more serious security hole than fopen_url, as bad as fopen_url is.


The above is if you have to include() instead of doing:

script type="text/javascript" src="http://somesite.com/cool.js"
Ah, I didn't catch the "same server" bit. Ray's right, you can use a server path to the files in domainA.com's path instead then.
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2011, 11:33 AM   #12
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
thanks guys for the help it's appreciated, i'm off out now, but i'll have a play around with those tomorrow and report back.

thanks again
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.