Bug #13207 Updated: open_basedir not restricting file access properly
| From: | mfischer@php.net | Date: | Mon, 03 Jun 2002 16:16:18 +0000 |
| Subject: | Bug #13207 Updated: open_basedir not restricting file access properly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-9337@lists.php.net to get a copy of this message | ||
ID: 13207
Updated by: mfischer@php.net
Reported By: jedi@tstonramp.com
-Status: Open
+Status: Bogus
Bug Type: IIS related
Operating System: NT 4.0
PHP Version: 4.0.6
New Comment:
Thank you for taking the time to report a problem with PHP.
Unfortunately your version of PHP is too old -- the problem
might already be fixed. Please download a new PHP
version from http://www.php.net/downloads.php
If you are able to reproduce the bug with one of the latest
versions of PHP, please change the PHP version on this bug report
to the version you tested and change the status back to "Open".
Again, thank you for your continued support of PHP.
Previous Comments:
------------------------------------------------------------------------
[2001-12-02 04:47:36] sander@php.net
Reproduced with 4.1.0RC4 on Windows 2000 with Apache 1.3.22!
Is this a bug or non-documented behaviour???
------------------------------------------------------------------------
[2001-11-11 12:20:29] sander@php.net
Try using a slahs (/) or a double backslash (\\) instead of a single
backslash. Does that work?
------------------------------------------------------------------------
[2001-09-10 02:20:12] jedi@tstonramp.com
Unless there is some other configuration I'm not aware of, I mentioned
in the bug report that I have open_basedir enabled in that it says
C:\inetpub
as my open_basedir value when I do phpinfo()
If there's something wrong with the path format, I guess I could
understand that, although I've seen other Win-style path formats in
phpinfo that take the same format.
------------------------------------------------------------------------
[2001-09-07 21:25:52] rasmus@php.net
You don't have open_basedir enabled. The error message from an
open_basedir restriction is not "permission denied". Does your
phpinfo() output tell you that open_basedir is in effect?
------------------------------------------------------------------------
[2001-09-07 19:09:40] jedi@tstonramp.com
Script is as follows:
mkdir("/test",0700);
phpinfo();
I'm running IIS 4.0 on NT 4.0 SP6. This code is running in my web
servers default web site. I AM doing Virtual Web hosting using Host
Header method, not multiple IPs. The anonymous web user for the virtual
web server in question let's say is called: anon
When the script is run and anon is *denied* permissions to C:\ the
following error is generated:
Warning: MkDir failed (Permission denied) in
C:\InetPub\wwwroot\php\test.php on line 2
and PHPInfo displays open_basedir as being: C:\inetpub
(This is good.)
When I go in and grant user anon "Change" privileges to C:\ (I do NOT
apply to all subdirectories) and re-run the script then:
I get NO error message and __THE DIRECTORY IS CREATED__ as C:\test
This is bad. VERY bad. I need to be able to rely on open_basedir
preventing __ANY__ file access outside of C:\inetpub.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=13207&edit=1