Req #79324 [Com]: Alternative to safe_mode_protected_env_vars
| From: | diego dot blanco at treitos dot com | Date: | Tue, 26 May 2020 22:45:07 +0000 |
| Subject: | Req #79324 [Com]: Alternative to safe_mode_protected_env_vars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227189@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79324&edit=1
ID: 79324
Comment by: diego dot blanco at treitos dot com
Reported by: diego dot blanco at treitos dot com
Summary: Alternative to safe_mode_protected_env_vars
Status: Open
Type: Feature/Change Request
Package: Scripting Engine problem
PHP Version: 7.4.3
Block user comment: N
Private report: N
New Comment:
Yes, it is possible to do it if you install a plugin to send mails via SMTP using localhost. The
default wordpress installation does not allow that.
Previous Comments:
------------------------------------------------------------------------
[2020-05-26 18:59:21] bugreports at gmail dot com
https://www.siteground.com/tutorials/wordpress/use-smtp/
------------------------------------------------------------------------
[2020-05-26 18:47:13] diego dot blanco at treitos dot com
> I don't know any software which don't support smtp via phpmailer and mail() is in
> disabled_functions() here since 2002 which is 18 years now.
I am afraid that Wordpress (version 5.4.1, latest as of today) relies by default on mail(). Despite
using PHPMailer, it seems to default to mail(). With mail() in disabled_functions, things like
password reset mails won't work.
I've been trying to workaround this but there isn't a good alternative. I wish this
wasn't disregarded so easily.
------------------------------------------------------------------------
[2020-03-01 18:12:26] diego dot blanco at treitos dot com
My point here is to have a sensible solution that has a minimal impact on end users and having a way
to limit what environment variables a user is able to set seems the right way.
There are users that still use mail() in their custom code. I agree that disabling mail() would
solve the problem (in case there aren't any other common external runtime calls) but that would
have impact in some users. Disabling putenv() will also solve the problem but again, although most
of the software does not require it, it is a feature that some users might miss.
In any case, I already said that I am ok with considering this a feature request. I just wanted to
give some more information regarding some of its security implications.
I think it could be useful to have some configuration that allowed to do this as it was possible in
the past. If you do not think that is the case, feel free to disregard this bug report and mark it
as wontfix.
------------------------------------------------------------------------
[2020-03-01 17:52:22] bugreports at gmail dot com
i don't know any software which don't support smtp via phpmailer and mail() is in
disabled_functions() here since 2002 which is 18 years now
------------------------------------------------------------------------
[2020-03-01 17:49:49] diego dot blanco at treitos dot com
Thank you for your clarification Nikic. I just wanted to give more information about the problem so
the implications are better understood. If you consider this is the right category, that is totally
fine for me.
Regarding disabling mail() for a secure setup, although I agree it would be safer, it is an expected
feature for most of legit users so disabling it is not as an easy choice as disabling shell_exec().
For this reason it is usually enabled and the use of LD_PRELOAD to bypass restrictions is well known
among web hackers (both white and black hats)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79324
--
Edit this bug report at https://bugs.php.net/bug.php?id=79324&edit=1