Re: PHP 4.0 Bug #5097: security hole in file open

From: Date: Sat, 17 Jun 2000 03:01:33 +0000
Subject: Re: PHP 4.0 Bug #5097: security hole in file open
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-21581@lists.php.net to get a copy of this message
You can compile apache with suEXEC, and build php in cgi mode. The php scripts will then run as the user that owns them. On 17 Jun 2000 greg@netserv.net.au wrote: > From: greg@netserv.net.au > Operating system: linux (redhat) > PHP version: 4.0 Beta 3 > PHP Bug Type: Other > Bug description: security hole in file open > > I am sorry if in my documentation search I have missed the way to block this. Especially if it > is just a configuration issuse. > I didnt want to post this to the php open list. > > As the http server runs as the same user as php then also any file that can be read by the > server can also be accessed on the local system by a fopen > Also seeing that the web root is also the root of the users web pages > Any one user can do a fopen on another users suposedly hidden php source > Is it possible to stop ../ changes in the global restrictions so users cant get out of their > home directories > > > <? > if (!($f = fopen("../other_user/secret.php","r"))){ > print ("cant open that") ; > exit; > } > while(!feof($f)){ > print (fgets($f,255)); > } > fclose($f); > ?> > > Thanks Greg > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.dev (#21581) next »