ENFORCE_SAFE_MODE
| From: | Andi Gutmans | Date: | Wed, 30 Aug 2000 19:59:32 +0000 |
| Subject: | ENFORCE_SAFE_MODE | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-31299@lists.php.net to get a copy of this message | ||
Some calls to php_fopen_wrappers() use the ENFORCE_SAFE_MODE #define and some don't. Actually on a whole if you're using include_path you can often circumvent the ENFORCE_SAFE_MODE option and still open a file which you're not supposed to open.
I am getting rid of it and am only checking PG(safe_mode) in fopen-wrappers.c. This should make the safe_mode much much safer from now on (at least the code that uses the php_fopen_wrappers()). I have heard in the past that some extension modules might want to open some system fonts and stuff so you wouldn't want to enable safe mode for those modules but I think it's a bad explanation. You could probably use those extensions to open /etc/passwd and maybe even get some kind of info back by chance.
If anyone thinks I'll break something badly scream now!
Andi
---
Andi Gutmans <andi@zend.com>
http://www.zend.com/