#20951 [Opn->]: PHP shell functions always call cmd.exe - potential security issue
| From: | edink@php.net | Date: | Fri, 27 Dec 2002 02:19:16 +0000 |
| Subject: | #20951 [Opn->]: PHP shell functions always call cmd.exe - potential security issue | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-28454@lists.php.net to get a copy of this message | ||
ID: 20951
Updated by: edink@php.net
Reported By: WPinegar@healthtech.net
-Status: Open
+Status: Won\'t fix
Bug Type: IIS related
Operating System: Windows .Net Server 2003 RC2
PHP Version: 4CVS-2002-12-11 (dev)
New Comment:
There were many other probmlems with executing applications from within
a web server environment that were solved by requiring the execution
through cmd /c. I guess system administrators would have to configure
there servers accordingly.
Previous Comments:
------------------------------------------------------------------------
[2002-12-11 23:16:20] WPinegar@healthtech.net
Windows.Net Server 2003 has instituted a new security measure that
causes problems with any of the shell related functions in PHP.
Windows.Net Server changes the ACL's on EXE's in the %windir%\system32
subdirectory. In particular CMD.EXE can no longer be executed by the
"anonymous" user account (ie, IUSR_COMPUTERNAME)--there is a specific
Deny ACL created by the Windows.Net Server installer. Since PHP calls
CMD.EXE to execute any external shell program PHP requires that CMD.EXE
be reconfigured for anonymous access anytime a PHP page needs to call
an external program. This design is no longer a good idea because PHP
forces the web administrator to open up a potential security hole in
the system by re-enabling access to CMD.EXE.
The shell functions in PHP should call the application directly instead
of always calling CMD.EXE? If the PHP programmer wants to call a
feature of the CMD intreperter then he should be forced to call the
shell command like
CMD /C dir *.*; Only then would the administrator
be required to allow access to the command intreperter.
Please consider this modification as it will make Windows.Net Server
more secure when running PHP. Or at least add configuration option to
PHP.INI that will modify the behavior of the shell functions to no
longer directly call CMD.EXE
Thank you!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=20951&edit=1