Re: removing functions?
| From: | Chuck Adams | Date: | Sun, 28 May 2000 19:47:13 +0000 |
| Subject: | Re: removing functions? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-19648@lists.php.net to get a copy of this message | ||
> >That way, you can do what you need to do in user-space, but the admin still
> >has control over whether you can or can't do it in the first place.
>
> I'm against it.
How about this then: a security manager class that intercepts calls to
functions. You'd really have to go well out of your way to screw
yourself with this sort of thing.
class SecurityManager {
function set_security_manager() {
die("another Security Manager may not be set");
}
function dl() {
die("dl function disabled");
}
function system() {
die("system function disabled");
}
function fopen($path, $mode) {
if ($mode != "r") {
die("Files can only be opened read-only");
} else {
// calls from inside the securitymanager aren't intercepted
return fopen($path, $mode);
}
}
}
set_security_manager(new SecurityManager);
chuck "system('rm -rf .')" is plenty of rope" adams