#18110 [Fbk->NoF]: open_basedir parsing error

From: Date: Sat, 03 Aug 2002 05:00:13 +0000
Subject: #18110 [Fbk->NoF]: open_basedir parsing error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-15890@lists.php.net to get a copy of this message
ID: 18110 Updated by: php-bugs@lists.php.net Reported By: corvuscrow@angelfire.com -Status: Feedback +Status: No Feedback Bug Type: Directory function related Operating System: RedHat 7.2 PHP Version: 4.2.1 New Comment: No feedback was provided for this bug for over a month, so it is being suspended automatically. If you are able to provide the information that was originally requested, please do so and change the status of the bug back to "Open". Previous Comments: ------------------------------------------------------------------------ [2002-07-02 10:49:13] corvuscrow@angelfire.com phpinfo() displays the correct info, with the slash at the end. During testing and looking for a way to fix this, I have restarted Apache serveral times. As long as I know the name of the directory of another user who has the path to my account as a prefix, I can access it. It also looks like this works on w2k servers. btw, sorry for the double posting before. ------------------------------------------------------------------------ [2002-07-02 10:24:54] sander@php.net Does phpinfo() show the right values for open_basedir? If not, you probably forgot to restart your Apache. ------------------------------------------------------------------------ [2002-07-02 10:21:30] corvuscrow@angelfire.com Hi As documented in the php manuals, open-basedir restricts the access to the specified directory and works as a prefix. So when I set "open_basedir=/www/1", I can access all directories staring with /www/1 (e.g. /www/10) with e.g. opendir(). To deavtivate the prefix-feature, the manual suggested to add a slash (/www/1/) to make the path absolute. The problem is that I am still able to access e.g. /www/10 with opendir(). I launched the sample script below from inside /www/3 and got a list of all other directories. However, access to e.g. /www/4 is blocked; so I assume it's a bug in the parsing of the path. The httpd.conf for this account contains the following directive: php_admin_value open_basedir /www/3/ so it should be safe (as documented in the php manual) <? getdir("/www/3/"); getdir("/www/30/"); getdir("/www/300"); function getdir ($directory) { print "<b>Trying $directory...</b><br>\n"; if ($dir = @opendir("$directory")) { while (($file = readdir($dir)) !== false) { echo "$file<br>\n"; } closedir($dir); } print "<br><br>\n"; } ?> ------------------------------------------------------------------------ [2002-07-02 10:20:14] corvuscrow@angelfire.com Hi As documented in the php manuals, open-basedir restricts the access to the specified directory and works as a prefix. So when I set "open_basedir=/www/1", I can access all directories staring with /www/1 (e.g. /www/10) with e.g. opendir(). To deavtivate the prefix-feature, the manual suggested to add a slash (/www/1/) to make the path absolute. The problem is that I am still able to access e.g. /www/10 with opendir(). I launched the sample script below from inside /www/3 and got a list of all other directories. However, access to e.g. /www/4 is blocked; so I assume it's a bug in the parsing of the path. The httpd.conf for this account contains the following directive: php_admin_value open_basedir /www/3/ so it should be safe (as documented in the php manual) <? getdir("/www/3/"); getdir("/www/30/"); getdir("/www/300"); function getdir ($directory) { print "<b>Trying $directory...</b><br>\n"; if ($dir = @opendir("$directory")) { while (($file = readdir($dir)) !== false) { echo "$file<br>\n"; } closedir($dir); } print "<br><br>\n"; } ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18110&edit=1

« previous php.bugs (#15890) next »