Re: PHP 4.0 Bug #5097: security hole in file open
| From: | bob at thestuff dot net | Date: | Sat, 17 Jun 2000 03:01:33 +0000 |
| Subject: | Re: PHP 4.0 Bug #5097: security hole in file open | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-21581@lists.php.net to get a copy of this message | ||
You can compile apache with suEXEC, and build php in cgi mode. The php
scripts will then run as the user that owns them.
On 17 Jun 2000 greg@netserv.net.au wrote:
> From: greg@netserv.net.au
> Operating system: linux (redhat)
> PHP version: 4.0 Beta 3
> PHP Bug Type: Other
> Bug description: security hole in file open
>
> I am sorry if in my documentation search I have missed the way to block this. Especially if it
> is just a configuration issuse.
> I didnt want to post this to the php open list.
>
> As the http server runs as the same user as php then also any file that can be read by the
> server can also be accessed on the local system by a fopen
> Also seeing that the web root is also the root of the users web pages
> Any one user can do a fopen on another users suposedly hidden php source
> Is it possible to stop ../ changes in the global restrictions so users cant get out of their
> home directories
>
>
> <?
> if (!($f = fopen("../other_user/secret.php","r"))){
> print ("cant open that") ;
> exit;
> }
> while(!feof($f)){
> print (fgets($f,255));
> }
> fclose($f);
> ?>
>
> Thanks Greg
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>