Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP

From: Date: Sat, 26 Aug 2000 14:22:26 +0000
Subject: Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-30741@lists.php.net to get a copy of this message
For production sites, you're encouraged not to display errors to end users at all, and instead log them: display_errors = On ; Print out errors (as a part of the HTML script) log_errors = Off ; Log errors into a log file (server-specific log, stderr, or error_log (below)) I'll add those suggestions to the php.ini-dist file. Zeev On 26 Aug 2000 joel@intwebservices.com wrote: > From: joel@intwebservices.com > Operating system: Windows NT 4.0 > PHP version: 4.0.1pl2 > PHP Bug Type: Other > Bug description: Security vulnerability for bad url file names with IIS PHP > > If you put a bad file name in the url the error message shows the hard drive directory > structure. > > No script necessary. > Just put any bad file name in a url for an IIS web server > > cgi version: > Fatal error: Unable to open S:\awebsites\websiteman\html\*a.php in Unknown on line 0 > > isapi version > Warning: Failed opening 'S:\awebsites\websiteman\html\*a.phpi' for inclusion > (include_path='') in Unknown on line 0 > > > -- Zeev Suraski <zeev@zend.com> http://www.zend.com/

« previous php.dev (#30741) next »