Why PHP may further to break authorization?

From: Date: Tue, 12 Sep 2000 05:31:16 +0000
Subject: Why PHP may further to break authorization?
Groups: php.dev 
Request: Send a blank email to php-dev+get-32991@lists.php.net to get a copy of this message
Hi, folks! Synopsys: both PHP3 and PHP4 further that any user even w/o required credentials can get info protected by .htaccess file. Details: IF I have a directory protected by .htacces file, and I give a full name of any script-file in this directory, I'll get output of this script instead of 401 Error Message, which I'm expecting to get.:( E.g., the right one: ======================== telnet host 80 Trying host... Connected to host. Escape character is '^]'. get /Adm/ http/1.0 Host: name.of.virtual HTTP/1.1 401 Authorization Required Date: Tue, 12 Sep 2000 05:10:32 GMT Server: Apache/1.3.12 (Unix) PHP/4.0.2 rus/PL29.7 Connection: close Content-Type: text/html; charset=koi8-r Expires: Thu, 01 Jan 1970 00:00:01 GMT Last-Modified: Tue, 12 Sep 2000 05:10:43 GMT <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <HTML><HEAD> <TITLE>401 Authorization Required</TITLE> </HEAD><BODY> <H1>Authorization Required</H1> This server could not verify that you are authorized to access the document [Error Page skipped] ====================== the wrong case: ====================== telnet host 80 Trying host... Connected to host. Escape character is '^]'. get /Adm/index.html http/1.0 Host: name.of.virtual HTTP/1.1 200 OK Date: Tue, 12 Sep 2000 05:15:35 GMT Server: Apache/1.3.12 (Unix) PHP/4.0.2 rus/PL29.7 X-Powered-By: PHP/4.0.2 Connection: close Content-Type: text/html; charset=koi8-r Expires: Thu, 01 Jan 1970 00:00:01 GMT Last-Modified: Tue, 12 Sep 2000 05:15:37 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <!-- [Protected Page skipped] ==================== Here the relevant configs... .htaccess: ============= AuthName EXAMPLE AuthType basic AuthUserFile /<fullpath>/.htpasswd <LIMIT GET POST> order deny,allow deny from all allow from all require valid-user </LIMIT> ============= relevant directives from httpd.conf: ============= <Directory "<fullpath>"> Options Indexes FollowSymLinks MultiViews AllowOverride AuthConfig Limit Options Order allow,deny Allow from all ..... AddType application/x-httpd-php .php AddType application/x-httpd-php .html ============= Replacing autorization directives to httpd.conf or access.conf doesn't help. This behaviour was observed on FreeBSD/PC 3.3,4.1, Linux/PC 2.2.16,2.2.15 and Solaris/Sparc 2.6. Any hints? -- WBR, Yury Bokhoncovich, SysAdmin at FIS. voice call: +7 (3832) 119727 pager: +7 (3832) 186555/61621 mailto: byg@fis.ru visit us: http://www.fis.ru/ Unix is like a wigwam -- no Gates, no Windows, and an Apache inside.

« previous php.dev (#32991) next »