Security ALERT
| From: | Eric KASTLER | Date: | Sun, 22 Oct 2000 12:53:42 +0000 |
| Subject: | Security ALERT | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-35649@lists.php.net to get a copy of this message | ||
<<comments to the new php-3.0.12-win32 should be send to my email address or
to php-dev@lists.php.net>>
I am using php-3.0.12-win32 and got the following message, CAN YOU HELP ME ?
:
<<Security Alert! PHP CGI cannot be accessed directly.
This PHP CGI binary was compiled with force-cgi-redirect enabled. This means
that a page will only be served up if the REDIRECT_STATUS CGI variable is
set. This variable is set, for example, by Apache's Action directive
redirect.
You may disable this restriction by recompiling the PHP binary with
the --disable-force-cgi-redirect switch. If you do this and you have your
PHP CGI binary accessible somewhere in your web tree, people will be able to
circumvent .htaccess security by loading files through the PHP parser. A
good way around this is to define doc_root in your php3.ini file to
something other than your top-level DOCUMENT_ROOT. This way you can separate
the part of your web space which uses PHP from the normal part using
.htaccess security. If you do not have any .htaccess restrictions anywhere
on your site you can leave doc_root undefined. >>
Thank you in advance !
Eric
e-mail : awpfr@compuserve.com