PHP 4.0 Bug #5097: security hole in file open

From: Date: Sat, 17 Jun 2000 02:58:52 +0000
Subject: PHP 4.0 Bug #5097: security hole in file open
Groups: php.dev 
Request: Send a blank email to php-dev+get-21580@lists.php.net to get a copy of this message
From: greg@netserv.net.au Operating system: linux (redhat) PHP version: 4.0 Beta 3 PHP Bug Type: Other Bug description: security hole in file open I am sorry if in my documentation search I have missed the way to block this. Especially if it is just a configuration issuse. I didnt want to post this to the php open list. As the http server runs as the same user as php then also any file that can be read by the server can also be accessed on the local system by a fopen Also seeing that the web root is also the root of the users web pages Any one user can do a fopen on another users suposedly hidden php source Is it possible to stop ../ changes in the global restrictions so users cant get out of their home directories <? if (!($f = fopen("../other_user/secret.php","r"))){ print ("cant open that") ; exit; } while(!feof($f)){ print (fgets($f,255)); } fclose($f); ?> Thanks Greg

« previous php.dev (#21580) next »