It works by including a remote file in an HTTP request ... and of course patch up the holes as quickly as possible when a new one is discovered. With RFI, as with SQLi, the problem is opening ...