Bug #18110 Updated: open_basedir parsing error
| From: | corvuscrow at angelfire dot com | Date: | Tue, 02 Jul 2002 14:21:31 +0000 |
| Subject: | Bug #18110 Updated: open_basedir parsing error | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-12805@lists.php.net to get a copy of this message | ||
ID: 18110
Updated by: corvuscrow@angelfire.com
-Reported By: sven@issociate.de
+Reported By: corvuscrow@angelfire.com
Status: Open
Bug Type: Directory function related
Operating System: RedHat 7.2
PHP Version: 4.2.1
New Comment:
Hi
As documented in the php manuals, open-basedir restricts the access to
the specified directory and works as a prefix. So when I set
"open_basedir=/www/1", I can access all directories staring with
/www/1
(e.g. /www/10) with e.g. opendir(). To deavtivate the prefix-feature,
the manual suggested to add a slash (/www/1/) to make the path
absolute.
The problem is that I am still able to access e.g. /www/10 with
opendir(). I launched the sample script below from inside /www/3 and
got
a list of all other directories. However, access to e.g. /www/4 is
blocked; so I assume it's a bug in the parsing of the path. The
httpd.conf for this account contains the following directive:
php_admin_value open_basedir /www/3/ so it should be safe (as
documented
in the php manual)
<?
getdir("/www/3/");
getdir("/www/30/");
getdir("/www/300");
function getdir ($directory)
{
print "<b>Trying $directory...</b><br>\n";
if ($dir = @opendir("$directory"))
{
while (($file = readdir($dir)) !== false)
{
echo "$file<br>\n";
}
closedir($dir);
}
print "<br><br>\n";
}
?>
Previous Comments:
------------------------------------------------------------------------
[2002-07-02 10:20:14] corvuscrow@angelfire.com
Hi
As documented in the php manuals, open-basedir restricts the access to
the specified directory and works as a prefix. So when I set
"open_basedir=/www/1", I can access all directories staring with /www/1
(e.g. /www/10) with e.g. opendir(). To deavtivate the prefix-feature,
the manual suggested to add a slash (/www/1/) to make the path
absolute.
The problem is that I am still able to access e.g. /www/10 with
opendir(). I launched the sample script below from inside /www/3 and
got a list of all other directories. However, access to e.g. /www/4 is
blocked; so I assume it's a bug in the parsing of the path. The
httpd.conf for this account contains the following directive:
php_admin_value open_basedir /www/3/ so it should be safe (as
documented in the php manual)
<?
getdir("/www/3/");
getdir("/www/30/");
getdir("/www/300");
function getdir ($directory)
{
print "<b>Trying $directory...</b><br>\n";
if ($dir = @opendir("$directory"))
{
while (($file = readdir($dir)) !== false)
{
echo "$file<br>\n";
}
closedir($dir);
}
print "<br><br>\n";
}
?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18110&edit=1