Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP
| From: | Zeev Suraski | Date: | Sat, 26 Aug 2000 14:22:26 +0000 |
| Subject: | Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30741@lists.php.net to get a copy of this message | ||
For production sites, you're encouraged not to display errors to end users
at all, and instead log them:
display_errors = On ; Print out errors (as a part of the HTML
script)
log_errors = Off ; Log errors into a log file
(server-specific log, stderr, or error_log (below))
I'll add those suggestions to the php.ini-dist file.
Zeev
On 26 Aug 2000 joel@intwebservices.com wrote:
> From: joel@intwebservices.com
> Operating system: Windows NT 4.0
> PHP version: 4.0.1pl2
> PHP Bug Type: Other
> Bug description: Security vulnerability for bad url file names with IIS PHP
>
> If you put a bad file name in the url the error message shows the hard drive directory
> structure.
>
> No script necessary.
> Just put any bad file name in a url for an IIS web server
>
> cgi version:
> Fatal error: Unable to open S:\awebsites\websiteman\html\*a.php in Unknown on line 0
>
> isapi version
> Warning: Failed opening 'S:\awebsites\websiteman\html\*a.phpi' for inclusion
> (include_path='') in Unknown on line 0
>
>
>
--
Zeev Suraski <zeev@zend.com>
http://www.zend.com/