Re: ENFORCE_SAFE_MODE

From: Date: Wed, 30 Aug 2000 21:04:18 +0000
Subject: Re: ENFORCE_SAFE_MODE
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31324@lists.php.net to get a copy of this message
At 23:53 30/08/2000, Rasmus Lerdorf wrote:
Security does come in the price of usability, quite often. The GD issue alone is a great example of why safe mode is not reliable. What GD issue? I have looked at imageloadfont() and really don't see an obvious exploit here. No security is ever absolute. We have also never advertised safe-mode as being ideal. It does however stop the obvious exploits and is as such useful to a number of people who don't require anything beyond that. Ideally this should not be done at the PHP level at all, but due to lack of better options we needed this stopgap. The better option is something I have been pushing for nearly two years now and it is coming in Apache-2.0. That is the per-VirtualHost user/group configuration setting. I am all for cleaning things up in the current code but lets keep the alarmist messages on this stuff to a minimum. Nothing you said in your message is new. I wrote the same message two years ago. Come up with a better alternative.
I never said it's new, even though your approach changed a bit (when I raised it a year ago, you said you don't think there are any issues with safe mode, and that it is fairly safe). I don't know how we advertised safe mode exactly. I'm not sure if we did. The obvious assumption end users make is that it's safe, and that they can rely on it. Another issue is that it looks much worse when an exploit is exposed on BugTraq. I'm in favour of clearly saying, in the manual, in php.ini-dist, or wherever safe mode is documented today - that it's inherently unsafe, and may be prone to bugs or unexpected side effects, that it's ok to guard against obvious 'attacks' uneducated, non professional users may make; But that it's not reliable as a safeguard against hackers. Zeev -- Zeev Suraski <zeev@zend.com> http://www.zend.com/

« previous php.dev (#31324) next »