Re: ENFORCE_SAFE_MODE
| From: | Zeev Suraski | Date: | Wed, 30 Aug 2000 20:25:34 +0000 |
| Subject: | Re: ENFORCE_SAFE_MODE | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31311@lists.php.net to get a copy of this message | ||
At 23:06 30/08/2000, Rasmus Lerdorf wrote:
I am getting rid of it and am only checking PG(safe_mode) in fopen-wrappers.c. This should make the safe_mode much much safer from now on (at least the code that uses the php_fopen_wrappers()). I have heard in the past that some extension modules might want to open some system fonts and stuff so you wouldn't want to enable safe mode for those modules but I think it's a bad explanation. You could probably use those extensions to open /etc/passwd and maybe even get some kind of info back by chance. If anyone thinks I'll break something badly scream now! Whether it is a bad explanation or not, you will break the GD extension as I explained before.I think we may want to pause the change itself, and instead discuss the safe mode feature more closely. Personally, I've always felt awkward about this feature, because we're promising something that we can't say we deliver. I don't know about you, but I'd never rely on PHP's safe mode code (which is fairly messy, by design) to be secure. The feeling we're giving people, though, is that it is secure. Security does come in the price of usability, quite often. The GD issue alone is a great example of why safe mode is not reliable. We've all seen much more innocent-looking pieces of code being exploited, it's quite reasonable that this hole, or others, are even much more easily exploitable. Last time I raised this concern it was dismissed, and by a matter of pure coincidence, PHP starred on BugTraq no longer than a week later, with two safe mode bugs (after it hasn't been on BugTraq for years). In my opinion, safe mode is by definition not reliable. The security issues it tries to address should, and in my opinion, can only be in the operating system level. We can't QA every line of code that every last CVSer submits to verify that it doesn't open a possible hole. Admitting that is, in my opinion, is more than just valid - it's a must. Giving a false sense of security is, again, in my opinion, much worse than warning about security issues, and telling people to run in chroot()'d environments. At this point, due to the legacy concerns of safe mode, I'm not sure what's the best possible thing to do. I'd go towards securing any obvious things we find (like the fopen_wrapper issue), but more importantly, document clearly that safe mode is NOT safe, and should not be relied upon for mission critical stuff. I'm interested to hear what others think about it. Zeev -- Zeev Suraski <zeev@zend.com> http://www.zend.com/