Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP
| From: | joel at intwebservices dot com | Date: | Sat, 26 Aug 2000 23:30:05 +0000 |
| Subject: | Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30792@lists.php.net to get a copy of this message | ||
Oh ok. Yes that fixed it.
I would suggest that probably should be the default installation.
--------------------
display_errors = Off log_errors = On error_log = c:\phpdefaulterr.txt---------------------- joel@intwebservices.com At 05:22 PM 8/26/00 +0300, you wrote:
For production sites, you're encouraged not to display errors to end users at all, and instead log them:display_errors = On ; Print out errors (as a part of the HTMLscript)log_errors = Off ; Log errors into a log file(server-specific log, stderr, or error_log (below)) I'll add those suggestions to the php.ini-dist file. Zeev On 26 Aug 2000 joel@intwebservices.com wrote:From: joel@intwebservices.comOperating system: Windows NT 4.0PHP version: 4.0.1pl2 PHP Bug Type: Other Bug description: Security vulnerability for bad url file names with IIS PHPIf you put a bad file name in the url the error message shows the hard drive directory structure. No script necessary. Just put any bad file name in a url for an IIS web server cgi version: Fatal error: Unable to open S:\awebsites\websiteman\html\*a.php in Unknown on line 0 isapi version Warning: Failed opening 'S:\awebsites\websiteman\html\*a.phpi' for inclusion (include_path='') in Unknown on line 0 -- Zeev Suraski <zeev@zend.com> http://www.zend.com/ -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net