Re: ENFORCE_SAFE_MODE
| From: | Andrei Zmievski | Date: | Wed, 30 Aug 2000 20:01:15 +0000 |
| Subject: | Re: ENFORCE_SAFE_MODE | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31300@lists.php.net to get a copy of this message | ||
On Wed, 30 Aug 2000, Andi Gutmans wrote:
> Some calls to php_fopen_wrappers() use the ENFORCE_SAFE_MODE #define and
> some don't. Actually on a whole if you're using include_path you can often
> circumvent the ENFORCE_SAFE_MODE option and still open a file which you're
> not supposed to open.
> I am getting rid of it and am only checking PG(safe_mode) in
> fopen-wrappers.c. This should make the safe_mode much much safer from now
> on (at least the code that uses the php_fopen_wrappers()). I have heard in
> the past that some extension modules might want to open some system fonts
> and stuff so you wouldn't want to enable safe mode for those modules but I
> think it's a bad explanation. You could probably use those extensions to
> open /etc/passwd and maybe even get some kind of info back by chance.
> If anyone thinks I'll break something badly scream now!
As long as you're working on changing php_fopen_wrappers(), I have a
wishlist item. Can it be generalized enough so that extensions can use
something like PG(include_path) to the files they need from user specified
list of directories?
-Andrei
"The secret of flying is to throw yourself
at the ground, and miss." -- Douglas Adams