Why PHP may further to break authorization?
| From: | Yury Bokhoncovich | Date: | Tue, 12 Sep 2000 05:31:16 +0000 |
| Subject: | Why PHP may further to break authorization? | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32991@lists.php.net to get a copy of this message | ||
Hi, folks!
Synopsys: both PHP3 and PHP4 further that any user even w/o required
credentials
can get info protected by .htaccess file.
Details: IF I have a directory protected by .htacces file, and I give a
full name of any
script-file in this directory, I'll get output of this script instead of
401 Error Message,
which I'm expecting to get.:(
E.g., the right one:
========================
telnet host 80
Trying host...
Connected to host.
Escape character is '^]'.
get /Adm/ http/1.0
Host: name.of.virtual
HTTP/1.1 401 Authorization Required
Date: Tue, 12 Sep 2000 05:10:32 GMT
Server: Apache/1.3.12 (Unix) PHP/4.0.2 rus/PL29.7
Connection: close
Content-Type: text/html; charset=koi8-r
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Tue, 12 Sep 2000 05:10:43 GMT
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>401 Authorization Required</TITLE>
</HEAD><BODY>
<H1>Authorization Required</H1>
This server could not verify that you
are authorized to access the document
[Error Page skipped]
======================
the wrong case:
======================
telnet host 80
Trying host...
Connected to host.
Escape character is '^]'.
get /Adm/index.html http/1.0
Host: name.of.virtual
HTTP/1.1 200 OK
Date: Tue, 12 Sep 2000 05:15:35 GMT
Server: Apache/1.3.12 (Unix) PHP/4.0.2 rus/PL29.7
X-Powered-By: PHP/4.0.2
Connection: close
Content-Type: text/html; charset=koi8-r
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Tue, 12 Sep 2000 05:15:37 GMT
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<!--
[Protected Page skipped]
====================
Here the relevant configs...
.htaccess:
=============
AuthName EXAMPLE
AuthType basic
AuthUserFile /<fullpath>/.htpasswd
<LIMIT GET POST>
order deny,allow
deny from all
allow from all
require valid-user
</LIMIT>
=============
relevant directives from httpd.conf:
=============
<Directory "<fullpath>">
Options Indexes FollowSymLinks MultiViews
AllowOverride AuthConfig Limit Options
Order allow,deny
Allow from all
.....
AddType application/x-httpd-php .php
AddType application/x-httpd-php .html
=============
Replacing autorization directives to httpd.conf or access.conf doesn't
help.
This behaviour was observed on FreeBSD/PC 3.3,4.1, Linux/PC
2.2.16,2.2.15 and Solaris/Sparc 2.6.
Any hints?
--
WBR, Yury Bokhoncovich,
SysAdmin at FIS.
voice call: +7 (3832) 119727 pager: +7 (3832) 186555/61621
mailto: byg@fis.ru visit us: http://www.fis.ru/
Unix is like a wigwam -- no Gates, no Windows, and an Apache inside.