PHP 4.0 Bug #5097: security hole in file open
| From: | greg at netserv dot net dot au | Date: | Sat, 17 Jun 2000 02:58:52 +0000 |
| Subject: | PHP 4.0 Bug #5097: security hole in file open | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-21580@lists.php.net to get a copy of this message | ||
From: greg@netserv.net.au
Operating system: linux (redhat)
PHP version: 4.0 Beta 3
PHP Bug Type: Other
Bug description: security hole in file open
I am sorry if in my documentation search I have missed the way to block this. Especially if it is
just a configuration issuse.
I didnt want to post this to the php open list.
As the http server runs as the same user as php then also any file that can be read by the server
can also be accessed on the local system by a fopen
Also seeing that the web root is also the root of the users web pages
Any one user can do a fopen on another users suposedly hidden php source
Is it possible to stop ../ changes in the global restrictions so users cant get out of their home
directories
<?
if (!($f = fopen("../other_user/secret.php","r"))){
print ("cant open that") ;
exit;
}
while(!feof($f)){
print (fgets($f,255));
}
fclose($f);
?>
Thanks Greg