#20689 [WFx]: php_admin_value disable_functions not working as it should

From: Date: Wed, 30 Apr 2003 16:50:22 +0000
Subject: #20689 [WFx]: php_admin_value disable_functions not working as it should
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38847@lists.php.net to get a copy of this message
ID: 20689 Updated by: philip@php.net Reported By: webmaster at walia dot com Status: Wont fix Bug Type: *Configuration Issues Operating System: w2k and linux both PHP Version: 4.2.3 New Comment: The fact that disable_functions must be set in php.ini (and not httpd.conf) is indeed documented under disable_functions, see: http://www.php.net/manual/en/features.safe-mode.php There is also an open documentation bug to document every directive that follows this behavior but nobody has answered this call. Here's that report: http://bugs.php.net/bug.php?id=11598 Previous Comments: ------------------------------------------------------------------------ [2003-04-30 11:33:08] bugs dot php at jensthebrain dot de Could you please change the documentation to reflect this behaviour? ------------------------------------------------------------------------ [2002-11-27 22:01:44] rasmus@php.net You can run multiple services. So simply run 2 Apaches on different ports. Stick a reverse proxy out in front to redirect the requests appropriately and so all requests will be coming in on port 80 from outside. But, this is not the appropriate place to teach you how to design a hosting solution. Do a bit of research on your own. ------------------------------------------------------------------------ [2002-11-27 21:56:51] webmaster at walia dot com cant run a seperate instance of apache on w2k when it is running as a service, can i ? and how to run a seperate instance of php? can you explain this a bit more in detail? ------------------------------------------------------------------------ [2002-11-27 21:17:36] rasmus@php.net So run a separate restricted instance of Apache/PHP for virtualhosts you want to restrict and a non-restricted one for the others. ------------------------------------------------------------------------ [2002-11-27 20:55:48] akaylaa at yahoo dot com Even if the performance penalty is huge, it would still be really nice to have that for security reasons. what is you are doing web hosting on windows and want to stop people from running system commands. the user can run a system command in his own folder, of course, but then he can also run a batch file that actually access files above his own folder even if safe mode is on and base dir is set. the problem will be running of the batch file. legally the user only used a php system command in his own folder, but the batch file can now go ahead and delete files on the server anywhere. so i personally consider this to be a bug, and a very serious one from the point of view of web hosting for the public. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/20689 -- Edit this bug report at http://bugs.php.net/?id=20689&edit=1

« previous php.bugs (#38847) next »