Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c
| From: | Adam Maccabee Trachtenberg | Date: | Fri, 19 Apr 2002 05:35:04 +0000 |
| Subject: | Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-11211@lists.php.net to get a copy of this message | ||
On Thu, 18 Apr 2002, Aaron Bannert wrote:
> aaron Thu Apr 18 18:10:58 2002 EDT
>
> Modified files:
> /php4/sapi/apache2filter sapi_apache2.c php_apache.h
> apache_config.c
> Log:
> This patch implements a new Apache2 directive called PHPINIDir that
> allows the specification of the php.ini directory from within the Apache
> configuration. If left unset, the default is to defer to the hard-coded
> php paths. When set, the supplied path is made relative to Apache's
> internal ServerRoot setting.
>
> Example:
> PHPINIDir "conf"
> # PHP will now look in the ServerRoot/conf directory for the php.ini file
I get this really gross feeling knowing we would allow people to
configure PHP to search for a php.ini file in a public web accessible
globally readable directory.
It just seems like it opens up the possibility of some security
exploit. I know the file is readable on my system, and I don't know of
any secret information stored in the file, and I know it's not linked
to from anywhere. But... Why take a risk by putting settings in a
place where people could find it?
Couldn't we just make it an absolute path? Or have it search the include_path?
-adam
--
adam maccabee trachtenberg
adam@trachtenberg.com