Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP

From: Date: Sat, 26 Aug 2000 23:30:05 +0000
Subject: Re: PHP 4.0 Bug #6366: Security vulnerability for bad url file names with IIS PHP
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-30792@lists.php.net to get a copy of this message
Oh ok. Yes that fixed it. I would suggest that probably should be the default installation. --------------------
display_errors  =       Off
log_errors              =       On
error_log       =       c:\phpdefaulterr.txt
---------------------- joel@intwebservices.com At 05:22 PM 8/26/00 +0300, you wrote:
For production sites, you're encouraged not to display errors to end users at all, and instead log them:
display_errors  =       On      ; Print out errors (as a part of the HTML
script)
log_errors              =       Off     ; Log errors into a log file
(server-specific log, stderr, or error_log (below)) I'll add those suggestions to the php.ini-dist file. Zeev On 26 Aug 2000 joel@intwebservices.com wrote:
From:             joel@intwebservices.com
Operating system: Windows NT 4.0
PHP version:      4.0.1pl2
PHP Bug Type:     Other
Bug description:  Security vulnerability for bad url file names with IIS PHP
If you put a bad file name in the url the error message shows the hard drive directory structure. No script necessary. Just put any bad file name in a url for an IIS web server cgi version: Fatal error: Unable to open S:\awebsites\websiteman\html\*a.php in Unknown on line 0 isapi version Warning: Failed opening 'S:\awebsites\websiteman\html\*a.phpi' for inclusion (include_path='') in Unknown on line 0 -- Zeev Suraski <zeev@zend.com> http://www.zend.com/ -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net


« previous php.dev (#30792) next »