#41156 [Csd]: url_fopen default value
| From: | derick@php.net | Date: | Sun, 22 Apr 2007 16:45:28 +0000 |
| Subject: | #41156 [Csd]: url_fopen default value | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-111782@lists.php.net to get a copy of this message | ||
ID: 41156
Updated by: derick@php.net
Reported By: c dot heutger at psw dot net
Status: Closed
Bug Type: PHP options/info functions
Operating System: irrelevant
PHP Version: 4.4.6
New Comment:
No, no new functionality will be added to the PHP 4.4 series - it is in
maintenance mode only.
Previous Comments:
------------------------------------------------------------------------
[2007-04-22 16:38:33] c dot heutger at psw dot net
Perhaps can be added also to new versions of 4.x?
------------------------------------------------------------------------
[2007-04-21 10:02:18] edink@php.net
This issue was addressed in the latest 5.2.x releases by disallowing
using remote files in include statements by default.
------------------------------------------------------------------------
[2007-04-21 09:37:34] c dot heutger at psw dot net
Description:
------------
Meanwhile you installed a big warning in PHP installation on
register_globals and default them to off, there is no warning at all and
it is per default on on url_fopen, although with using of includes, this
variable opens any hackers from outside a door inside your applications
(e.g. used by opensurveypilot). So we had in the last time many hackins
as this variable is on either by default installation or by templates
like distributed via SWsofts Virtuozzo or with Plesk. This value should
be warned the same and set to off by default like the register_globals.
Reproduce code:
---------------
Try to refer any http:// ressource in e.g. opensurveypilot files using
include and url_fopen is on
Expected result:
----------------
Hacked sites if it's like default
url_fopen off by default in future PHP versions
Actual result:
--------------
A big security whole for lame code and programmers still open.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=41156&edit=1