two questions
| From: | Tom Duffey | Date: | Mon, 10 Jul 2000 06:29:58 +0000 |
| Subject: | two questions | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-23994@lists.php.net to get a copy of this message | ||
Dear PHP Developers,
1) If I set something like "php_admin_flag safe_mode 'on'" in the
<VirtualHost> section of Apache's httpd.conf, is it possible to stop
users from simply placing "php_flag safe_mode 'off'" in their .htaccess,
thus defeating the safe mode I hoped to enable via httpd.conf? I'm
running PHP 4.0.0 and would like to enable safe mode only on particular
Apache virtual hosts.
2) With safe mode enabled, how is it possible to accomplish something
like:
passthru ("cat \"filename with spaces.txt\"");
With safe mode enabled, this fails whenever I enclose the paramater (in
this case, a filename with spaces) in double-quotes. PHP seems to be
using EscapeShellCmd() on the exec() paramater which, unfortunately, ends
up escaping the double-quotes and makes the command fail. In the above
case, I see:
cat: spaces.txt": No such file or directory
I have tried storing the filename in a string and then doing something
like:
passthru("cat ".addslashes($file));
but now PHP escapes everything addslashes() just escaped making the call
useless again. If this were not the case then I could enable safe mode in
php.ini and problem 1 would go away :)
Best Regards,
Tom Duffey