PHP 4.0 Bug #7217: Security Problem with "include_dir" configuration
| From: | afader at asqnet dot org | Date: | Sun, 15 Oct 2000 07:49:55 +0000 |
| Subject: | PHP 4.0 Bug #7217: Security Problem with "include_dir" configuration | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-35038@lists.php.net to get a copy of this message | ||
From: afader@asqnet.org
Operating system: linux
PHP version: 4.0.2
PHP Bug Type: Feature/Change Request
Bug description: Security Problem with "include_dir" configuration
Okay - set up a common script directory. /home/httpd/phpi
in php.ini - set include_dir = .:/home/httpd/phpi
set safe_mode on.
Put a file into the directory. Call it "counter.inc"
make the owner of counter.inc any user and any group.
make a web page with a different user in the same group.
the web page cannot include("counter.inc"); you get a warning: SAFE MODE that uid 1
<> uid 2.
This makes it impossible to have shared php includes across multiple users.
- REQUEST -
Allow some way for SAFE MODE to ignore user matching on a selected directory (or set of
directories.) Or ignore matching for a specific userid/or/groupid on the target files???
Or, let me know what I'm doing wrong???
- Thanks -
Alexander
p.s. PHP rules ;-)
--
Edit Bug report at: http://bugs.php.net/?id=7217&edit=1