safe_mode.c hack - segmentation fault [PHP-DEV]

From: Date: Thu, 30 Mar 2000 08:22:25 +0000
Subject: safe_mode.c hack - segmentation fault [PHP-DEV]
Groups: php.dev 
Request: Send a blank email to php-dev+get-17399@lists.php.net to get a copy of this message
Hi all, It appears that safe mode is a much neglected aspect of PHP (been using PHP since the FI days). One of the things I need to add to safe mode is the restriction preventing script going above their own current directory (regardless of UID). To this end I wrote the following code which works perfectly in "standalone" mode (i.e. a .c prog with the call in main()): #include <stdio.h> #include <stdlib.h> /* checkDirs * * This function is a TIBUS modification to ensure that PHP scripts cannot * access files outside of its own directory when running in SAFE_MODE. * */ int checkDirs( char *script, char *filename) { char *scriptdir[255], *search[255]; int i=0; int slash=47; int checklength=0, result=1; long pos=0, start=0; for (i=0;i<255;i++) { scriptdir[i]='\0'; search[i]='\0'; } pos = strrchr(script, slash); i = (pos - (long)script); printf("1 - script=%s\n filename=%s\n i=%d \n",script,filename,i ); if (i<0 || i>255) return 2; i++; strncpy(scriptdir,script,i); scriptdir[i] = '\0'; if (i > (int)strlen(filename) ){ return 3; } result = strncmp( scriptdir, filename, i ); if( result == 0 ) return 0; else return 1; } The above function goes in the safe_mode.c file and in the checkuid function right after the check to see if it is a URL: me = getenv("SCRIPT_FILENAME"); if (checkDirs(me, fn) != 0){ php_error(E_WARNING, "SAFE MODE Restriction in effect. You canno t access files outside of the current directory.") ; return(0); } As I said, in a standalone prog the code works properly, however when I patch it into safe mode it gives a Segmentation fault (when trying to execute PHP). [Tue Mar 28 18:51:32 2000] [notice] child pid 34160 exit signal Segmentation fau lt (11) [Tue Mar 28 18:51:35 2000] [notice] child pid 34161 exit signal Segmentation fau lt (11) Turning safemode off in the php.ini file, it doesn't cause an error, but I obviously then don't have the protection I desire. Rasmus? anyone? Regards, Paul. -- Email pgregg at tibus.net | T: +44 (0) 1232 424190 | CLUB24 INTERNET | Technical Director | F: +44 (0) 1232 424709 | Free Access | The Internet Business Ltd | W: http://www.tibus.net | www.club24.co.uk |

« previous php.dev (#17399) next »