Req #20054 [Com]: safe_mode_include_dir not being used correctly

From: Date: Wed, 23 Mar 2022 05:23:12 +0000
Subject: Req #20054 [Com]: safe_mode_include_dir not being used correctly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-240458@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=20054&edit=1

 ID:                 20054
 Comment by:         giw42161 at uooos dot com
 Reported by:        public at cs dot uwa dot edu dot au
 Summary:            safe_mode_include_dir not being used correctly
 Status:             Wont fix
 Type:               Feature/Change Request
 Package:            Safe Mode/open_basedir
 Operating System:   Linux - Redhat 7.3
 PHP Version:        4.3.0-dev
 Block user comment: N
 Private report:     N

 New Comment:

Century Law Firm is the best team of lawyers for divorce case, Drt Case, High Court Matter, Civil
and Criminal Cases and more in Delhi. 
(https://centurylawfirm.in/)gist.github.com


Previous Comments:
------------------------------------------------------------------------
[2010-11-18 12:32:53] jani@php.net

Safe mode will be gone soon. This will never happen in older releases either.

------------------------------------------------------------------------
[2004-03-29 03:53:13] 99 at 9988 dot idv dot tw

d

------------------------------------------------------------------------
[2003-07-21 19:06:28] iliaa@php.net

The safe_mode_include_dir as it's name suggests is specifically tailored to allow
include/require exceptions that are READ only. If what you ask is to be implemented it could open a
number of security holes by allowing write/create/overwrite access to execluded directories. The
corect solution would be to add another directive where you could specify a list of excluded
directories inside user will have full access regardless of safe_mode. Since this already more of a
feature request rather then a bug I am marking it as such.

------------------------------------------------------------------------
[2002-11-20 00:53:49] public at cs dot uwa dot edu dot au

Just for the record, I wrote a patch for this to allow for paths to be excluded from the safemode
checks basically the same as the include value does.  Posted that the the developers list asking if
anyone was interested, enver got a reply, so I thought I'd add it in here for completeness
sake.

    If anyone has any suggestions with what I can do with the patch, let me know :}

------------------------------------------------------------------------
[2002-11-02 01:30:40] vegaspctech at yahoo dot com

I've got Apache 2 and PHP 4.3.0-dev on Red Hat 7.2 with /usr/share/pear in
safe_mode_include_dir and I get "SAFE MODE Restriction in effect.  The script whose uid is 502
is not allowed to access /usr/share/pear/Mail.php owned by uid 0" etc., with
'require_once( "Mail.php" );' and 'require( "Mail.php" );'
and 'include( "Mail.php" );' and 'include(
"/usr/share/pear/Mail.php" );' and every other variation I can think to try.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=20054


--
Edit this bug report at https://bugs.php.net/bug.php?id=20054&edit=1


Thread (9 messages)

« previous php.bugs (#240458) next »