#20689 [WFx]: php_admin_value disable_functions not working as it should
| From: | philip@php.net | Date: | Wed, 30 Apr 2003 16:50:22 +0000 |
| Subject: | #20689 [WFx]: php_admin_value disable_functions not working as it should | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38847@lists.php.net to get a copy of this message | ||
ID: 20689
Updated by: philip@php.net
Reported By: webmaster at walia dot com
Status: Wont fix
Bug Type: *Configuration Issues
Operating System: w2k and linux both
PHP Version: 4.2.3
New Comment:
The fact that disable_functions must be set in php.ini (and not
httpd.conf) is indeed documented under disable_functions, see:
http://www.php.net/manual/en/features.safe-mode.php
There is also an open documentation bug to document every directive
that follows this behavior but nobody has answered this call. Here's
that report:
http://bugs.php.net/bug.php?id=11598
Previous Comments:
------------------------------------------------------------------------
[2003-04-30 11:33:08] bugs dot php at jensthebrain dot de
Could you please change the documentation to reflect this behaviour?
------------------------------------------------------------------------
[2002-11-27 22:01:44] rasmus@php.net
You can run multiple services. So simply run 2 Apaches on different
ports. Stick a reverse proxy out in front to redirect the requests
appropriately and so all requests will be coming in on port 80 from
outside. But, this is not the appropriate place to teach you how to
design a hosting solution. Do a bit of research on your own.
------------------------------------------------------------------------
[2002-11-27 21:56:51] webmaster at walia dot com
cant run a seperate instance of apache on w2k when it is running as a
service, can i ? and how to run a seperate instance of php?
can you explain this a bit more in detail?
------------------------------------------------------------------------
[2002-11-27 21:17:36] rasmus@php.net
So run a separate restricted instance of Apache/PHP for virtualhosts
you want to restrict and a non-restricted one for the others.
------------------------------------------------------------------------
[2002-11-27 20:55:48] akaylaa at yahoo dot com
Even if the performance penalty is huge, it would still be really nice
to have that for security reasons.
what is you are doing web hosting on windows and want to stop people
from running system commands. the user can run a system command in his
own folder, of course, but then he can also run a batch file that
actually access files above his own folder even if safe mode is on and
base dir is set.
the problem will be running of the batch file. legally the user only
used a php system command in his own folder, but the batch file can now
go ahead and delete files on the server anywhere.
so i personally consider this to be a bug, and a very serious one from
the point of view of web hosting for the public.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/20689
--
Edit this bug report at http://bugs.php.net/?id=20689&edit=1