Re: safe_mode.c patch - segmentation fault

From: Date: Mon, 03 Apr 2000 23:02:24 +0000
Subject: Re: safe_mode.c patch - segmentation fault
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-17574@lists.php.net to get a copy of this message
Reposted: I've now recoded this function to use DJBs byte_* string libraries (DJB of qmail fame). Again works perfectly in standalone C prog mode, but when I merge it into php (latest version 4 beta) it causes apache to segfault: [Mon Apr 3 18:49:11 2000] [error] PHP Warning: Running php_checkuid on inc.txt: in /web/test.devcustserver.tibus.com/test.php3 on line 11 [Mon Apr 3 18:49:11 2000] [notice] child pid 10634 exit signal Segmentation fault (11) Can someone please provide me a dummy's pointer on where I can start to debug this and/or get it working. Once it runs I'd be happy if the powers-that-be wished to include this extra safe_mode option into the standard build (this makes Mass-hosting PHP on non-uid based apache systems viable). Thanks, Paul. Paul Gregg <pgregg-php-dev@niweb.com> wrote: > Hi all, > It appears that safe mode is a much neglected aspect of PHP (been using PHP > since the FI days). One of the things I need to add to safe mode is > the restriction preventing script going above their own current directory > (regardless of UID). > To this end I wrote the following code which works perfectly in "standalone" > mode (i.e. a .c prog with the call in main()): > #include <stdio.h> > #include <stdlib.h> > /* checkDirs > * > * This function is a TIBUS modification to ensure that PHP scripts cannot > * access files outside of its own directory when running in SAFE_MODE. > * > */ > int checkDirs( char *script, char *filename) { > char *scriptdir[255], *search[255]; > int i=0; > int slash=47; > int checklength=0, result=1; > long pos=0, start=0; > for (i=0;i<255;i++) { > scriptdir[i]='\0'; > search[i]='\0'; > } > pos = strrchr(script, slash); > i = (pos - (long)script); > printf("1 - script=%s\n filename=%s\n i=%d \n",script,filename,i ); > if (i<0 || i>255) > return 2; > i++; > strncpy(scriptdir,script,i); > scriptdir[i] = '\0'; > if (i > (int)strlen(filename) ){ > return 3; > } > result = strncmp( scriptdir, filename, i ); > if( result == 0 ) > return 0; > else > return 1; > } > The above function goes in the safe_mode.c file and in the checkuid function > right after the check to see if it is a URL: > me = getenv("SCRIPT_FILENAME"); > if (checkDirs(me, fn) != 0){ > php_error(E_WARNING, "SAFE MODE Restriction in effect. You canno > t access files outside of the current directory.") > ; > return(0); > } > As I said, in a standalone prog the code works properly, however when I patch > it into safe mode it gives a Segmentation fault (when trying to execute PHP). > [Tue Mar 28 18:51:32 2000] [notice] child pid 34160 exit signal Segmentation fau > lt (11) > [Tue Mar 28 18:51:35 2000] [notice] child pid 34161 exit signal Segmentation fau > lt (11) > Turning safemode off in the php.ini file, it doesn't cause an error, but I > obviously then don't have the protection I desire. > Rasmus? anyone? > Regards, > Paul. > -- > Email pgregg at tibus.net | T: +44 (0) 1232 424190 | CLUB24 INTERNET | > Technical Director | F: +44 (0) 1232 424709 | Free Access | > The Internet Business Ltd | W: http://www.tibus.net | > www.club24.co.uk | > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- Email pgregg at tibus.net | T: +44 (0) 1232 424190 | CLUB24 INTERNET | Technical Director | F: +44 (0) 1232 424709 | Free Access | The Internet Business Ltd | W: http://www.tibus.net | www.club24.co.uk |

« previous php.dev (#17574) next »