Re: safe_mode.c patch - segmentation fault
| From: | Paul Gregg | Date: | Mon, 03 Apr 2000 23:02:24 +0000 |
| Subject: | Re: safe_mode.c patch - segmentation fault | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-17574@lists.php.net to get a copy of this message | ||
Reposted:
I've now recoded this function to use DJBs byte_* string libraries (DJB
of qmail fame). Again works perfectly in standalone C prog mode, but when
I merge it into php (latest version 4 beta) it causes apache to segfault:
[Mon Apr 3 18:49:11 2000] [error] PHP Warning: Running php_checkuid on inc.txt: in
/web/test.devcustserver.tibus.com/test.php3 on line 11
[Mon Apr 3 18:49:11 2000] [notice] child pid 10634 exit signal Segmentation fault (11)
Can someone please provide me a dummy's pointer on where I can start to debug
this and/or get it working. Once it runs I'd be happy if the powers-that-be
wished to include this extra safe_mode option into the standard build (this
makes Mass-hosting PHP on non-uid based apache systems viable).
Thanks,
Paul.
Paul Gregg <pgregg-php-dev@niweb.com> wrote:
> Hi all,
> It appears that safe mode is a much neglected aspect of PHP (been using PHP
> since the FI days). One of the things I need to add to safe mode is
> the restriction preventing script going above their own current directory
> (regardless of UID).
> To this end I wrote the following code which works perfectly in "standalone"
> mode (i.e. a .c prog with the call in main()):
> #include <stdio.h>
> #include <stdlib.h>
> /* checkDirs
> *
> * This function is a TIBUS modification to ensure that PHP scripts cannot
> * access files outside of its own directory when running in SAFE_MODE.
> *
> */
> int checkDirs( char *script, char *filename) {
> char *scriptdir[255], *search[255];
> int i=0;
> int slash=47;
> int checklength=0, result=1;
> long pos=0, start=0;
> for (i=0;i<255;i++) {
> scriptdir[i]='\0';
> search[i]='\0';
> }
> pos = strrchr(script, slash);
> i = (pos - (long)script);
> printf("1 - script=%s\n filename=%s\n i=%d \n",script,filename,i );
> if (i<0 || i>255)
> return 2;
> i++;
> strncpy(scriptdir,script,i);
> scriptdir[i] = '\0';
> if (i > (int)strlen(filename) ){
> return 3;
> }
> result = strncmp( scriptdir, filename, i );
> if( result == 0 )
> return 0;
> else
> return 1;
> }
> The above function goes in the safe_mode.c file and in the checkuid function
> right after the check to see if it is a URL:
> me = getenv("SCRIPT_FILENAME");
> if (checkDirs(me, fn) != 0){
> php_error(E_WARNING, "SAFE MODE Restriction in effect. You canno
> t access files outside of the current directory.")
> ;
> return(0);
> }
> As I said, in a standalone prog the code works properly, however when I patch
> it into safe mode it gives a Segmentation fault (when trying to execute PHP).
> [Tue Mar 28 18:51:32 2000] [notice] child pid 34160 exit signal Segmentation fau
> lt (11)
> [Tue Mar 28 18:51:35 2000] [notice] child pid 34161 exit signal Segmentation fau
> lt (11)
> Turning safemode off in the php.ini file, it doesn't cause an error, but I
> obviously then don't have the protection I desire.
> Rasmus? anyone?
> Regards,
> Paul.
> --
> Email pgregg at tibus.net | T: +44 (0) 1232 424190 | CLUB24 INTERNET |
> Technical Director | F: +44 (0) 1232 424709 | Free Access |
> The Internet Business Ltd | W: http://www.tibus.net |
> www.club24.co.uk |
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Email pgregg at tibus.net | T: +44 (0) 1232 424190 | CLUB24 INTERNET |
Technical Director | F: +44 (0) 1232 424709 | Free Access |
The Internet Business Ltd | W: http://www.tibus.net |
www.club24.co.uk |