#22368 [Com]: safe mode on allows users to include (read) system files
ID: 22368
Comment by: phpspam at youknow dot com
Reported By: phpspam at overclockersclub dot com
Status: Bogus
Bug Type: PHP options/info functions
Operating System: Red Hat 7.2 Linux
PHP Version: 4.3.1
New Comment:
PHP is NOT ran by root in this case, and the /etc/passwd is owned by
root.
Previous Comments:
------------------------------------------------------------------------
[2003-02-22 14:10:32] iliaa@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
Safemode prevents PHP from opening files owned by a user different from
the one PHP is running as. If you /etc/passwd is owned by root and your
PHP runs as root safe_mode will not stop PHP from opening the file.
------------------------------------------------------------------------
[2003-02-21 20:51:02] phpspam at overclockersclub dot com
Safe Mode appears to be on, it says its on for local and master via
phpinfo() script. I can virtual include /etc/passwd and it will shows
the contents of the file. However, "some" function appear to be blocked
by safe mode.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=22368&edit=1
Thread (3 messages)