Re: ENFORCE_SAFE_MODE
| From: | Andi Gutmans | Date: | Wed, 30 Aug 2000 20:19:24 +0000 |
| Subject: | Re: ENFORCE_SAFE_MODE | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31303@lists.php.net to get a copy of this message | ||
At 01:06 PM 8/30/00 -0700, Rasmus Lerdorf wrote:
I am getting rid of it and am only checking PG(safe_mode) in fopen-wrappers.c. This should make the safe_mode much much safer from now on (at least the code that uses the php_fopen_wrappers()). I have heard in the past that some extension modules might want to open some system fonts and stuff so you wouldn't want to enable safe mode for those modules but I think it's a bad explanation. You could probably use those extensions to open /etc/passwd and maybe even get some kind of info back by chance. If anyone thinks I'll break something badly scream now! Whether it is a bad explanation or not, you will break the GD extension as I explained before.Well what do you suggest instead? Why not chown() the GD files over to nobody if they should be used with the web site? How do you know that the modules which don't have ENABLE_SAFE_MODE enabled don't give you any way to see the raw data in the files? And it also seems as if there were wholes with this in php_fopen_wrappers() under certain circumstances (where include_path wasn't defined). Andi --- Andi Gutmans <andi@zend.com> http://www.zend.com/