#22410 [Opn]: broader apache-php security options

From: Date: Wed, 30 Apr 2003 16:20:20 +0000
Subject: #22410 [Opn]: broader apache-php security options
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38842@lists.php.net to get a copy of this message
ID: 22410 User updated by: greg at laundrymat dot tv -Summary: braoder apache-php security options Reported By: greg at laundrymat dot tv Status: Open Bug Type: Feature/Change Request Operating System: redhat 7.0 PHP Version: 4.3.0 New Comment: Will someone please address this security issue. It's huge! Previous Comments: ------------------------------------------------------------------------ [2003-02-25 03:05:43] greg at laundrymat dot tv I really think there needs to be a way to prohibit system() ticker, or exec() on a per directory basis via the apache conf file. Safe mode is too restrictive and open_basedir doesn't work with these commands. Either make open base_dir actually work on all functions or create a way to shut these functions or any fuction off on a per directory basis. Its really is a must. I have a site that gives clients ftp access, A script could read the majority of the files on my server using the ticker and the vi commands. Thanks Greg Greenhaw ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=22410&edit=1

« previous php.bugs (#38842) next »