#22410 [Opn]: broader apache-php security options
| From: | greg at laundrymat dot tv | Date: | Wed, 30 Apr 2003 16:20:20 +0000 |
| Subject: | #22410 [Opn]: broader apache-php security options | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38842@lists.php.net to get a copy of this message | ||
ID: 22410
User updated by: greg at laundrymat dot tv
-Summary: braoder apache-php security options
Reported By: greg at laundrymat dot tv
Status: Open
Bug Type: Feature/Change Request
Operating System: redhat 7.0
PHP Version: 4.3.0
New Comment:
Will someone please address this security issue. It's huge!
Previous Comments:
------------------------------------------------------------------------
[2003-02-25 03:05:43] greg at laundrymat dot tv
I really think there needs to be a way to prohibit system()
ticker, or exec() on a per directory basis via the apache
conf file. Safe mode is too restrictive and open_basedir
doesn't work with these commands. Either make open
base_dir actually work on all functions or create a way to
shut these functions or any fuction off on a per directory
basis.
Its really is a must. I have a site that gives clients ftp
access, A script could read the majority of the files on my
server using the ticker and the vi commands.
Thanks
Greg Greenhaw
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=22410&edit=1