Re: Why PHP may further to break authorization?
| From: | Rasmus Lerdorf | Date: | Tue, 12 Sep 2000 01:52:43 +0000 |
| Subject: | Re: Why PHP may further to break authorization? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32996@lists.php.net to get a copy of this message | ||
> Synopsys: both PHP3 and PHP4 further that any user even w/o required
> credentials
> can get info protected by .htaccess file.
>
> Details: IF I have a directory protected by .htacces file, and I give a
> full name of any
> script-file in this directory, I'll get output of this script instead of
> 401 Error Message,
> which I'm expecting to get.:(
Then your Apache config is completely messed up. Apache does the access
check long before it calls the content handling hook (which is where PHP
gets called), so if there is a bug it could not possibly be in PHP.
You need to read up on Apache auth stuff. You are using a <LIMIT GET
POST> block. All I have to do to get around this is send you a PUT
request.
-Rasmus