Re: Why PHP may further to break authorization?

From: Date: Tue, 12 Sep 2000 06:44:20 +0000
Subject: Re: Why PHP may further to break authorization?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-33003@lists.php.net to get a copy of this message
Hi! Rasmus Lerdorf wrote: > > > Synopsys: both PHP3 and PHP4 further that any user even w/o required > > credentials > > can get info protected by .htaccess file. > > > > Details: IF I have a directory protected by .htacces file, and I give a > > full name of any > > script-file in this directory, I'll get output of this script instead of > > 401 Error Message, > > which I'm expecting to get.:( > > Then your Apache config is completely messed up. Apache does the access > check long before it calls the content handling hook (which is where PHP > gets called), so if there is a bug it could not possibly be in PHP. > Well, but why my Apache is working fine if I have compiled it w/o PHP at all? I.e. I eager to say that the issue disappears if Apache was compiled with the same options but PHP engine. > You need to read up on Apache auth stuff. You are using a <LIMIT GET Yep. Moving "require" directive out of LIMIT block has solved the issue. > POST> block. All I have to do to get around this is send you a PUT > request. Didn't catch you exactly, did you mean that another method (PUT and so on) is working anyway? -- WBR, Yury Bokhoncovich, SysAdmin at FIS. voice call: +7 (3832) 119727 pager: +7 (3832) 186555/61621 mailto: byg@fis.ru visit us: http://www.fis.ru/ Unix is like a wigwam -- no Gates, no Windows, and an Apache inside.

« previous php.dev (#33003) next »