Bug #18110 Updated: open_basedir parsing error

From: Date: Tue, 02 Jul 2002 14:24:54 +0000
Subject: Bug #18110 Updated: open_basedir parsing error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-12806@lists.php.net to get a copy of this message
ID: 18110 Updated by: sander@php.net Reported By: corvuscrow@angelfire.com -Status: Open +Status: Feedback Bug Type: Directory function related Operating System: RedHat 7.2 PHP Version: 4.2.1 New Comment: Does phpinfo() show the right values for open_basedir? If not, you probably forgot to restart your Apache. Previous Comments: ------------------------------------------------------------------------ [2002-07-02 10:21:30] corvuscrow@angelfire.com Hi As documented in the php manuals, open-basedir restricts the access to the specified directory and works as a prefix. So when I set "open_basedir=/www/1", I can access all directories staring with /www/1 (e.g. /www/10) with e.g. opendir(). To deavtivate the prefix-feature, the manual suggested to add a slash (/www/1/) to make the path absolute. The problem is that I am still able to access e.g. /www/10 with opendir(). I launched the sample script below from inside /www/3 and got a list of all other directories. However, access to e.g. /www/4 is blocked; so I assume it's a bug in the parsing of the path. The httpd.conf for this account contains the following directive: php_admin_value open_basedir /www/3/ so it should be safe (as documented in the php manual) <? getdir("/www/3/"); getdir("/www/30/"); getdir("/www/300"); function getdir ($directory) { print "<b>Trying $directory...</b><br>\n"; if ($dir = @opendir("$directory")) { while (($file = readdir($dir)) !== false) { echo "$file<br>\n"; } closedir($dir); } print "<br><br>\n"; } ?> ------------------------------------------------------------------------ [2002-07-02 10:20:14] corvuscrow@angelfire.com Hi As documented in the php manuals, open-basedir restricts the access to the specified directory and works as a prefix. So when I set "open_basedir=/www/1", I can access all directories staring with /www/1 (e.g. /www/10) with e.g. opendir(). To deavtivate the prefix-feature, the manual suggested to add a slash (/www/1/) to make the path absolute. The problem is that I am still able to access e.g. /www/10 with opendir(). I launched the sample script below from inside /www/3 and got a list of all other directories. However, access to e.g. /www/4 is blocked; so I assume it's a bug in the parsing of the path. The httpd.conf for this account contains the following directive: php_admin_value open_basedir /www/3/ so it should be safe (as documented in the php manual) <? getdir("/www/3/"); getdir("/www/30/"); getdir("/www/300"); function getdir ($directory) { print "<b>Trying $directory...</b><br>\n"; if ($dir = @opendir("$directory")) { while (($file = readdir($dir)) !== false) { echo "$file<br>\n"; } closedir($dir); } print "<br><br>\n"; } ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18110&edit=1

« previous php.bugs (#12806) next »