Re: Security ALERT

From: Date: Fri, 20 Oct 2000 13:34:26 +0000
Subject: Re: Security ALERT
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-35650@lists.php.net to get a copy of this message
Erhm, I would say RTFM to this, see: http://www.php.net/manual/html/security.html Derick Eric KASTLER wrote: > <<comments to the new php-3.0.12-win32 should be send to my email address or > to php-dev@lists.php.net>> > > I am using php-3.0.12-win32 and got the following message, CAN YOU HELP ME ? > : > > <<Security Alert! PHP CGI cannot be accessed directly. > This PHP CGI binary was compiled with force-cgi-redirect enabled. This means > that a page will only be served up if the REDIRECT_STATUS CGI variable is > set. This variable is set, for example, by Apache's Action directive > redirect. > You may disable this restriction by recompiling the PHP binary with > the --disable-force-cgi-redirect switch. If you do this and you have your > PHP CGI binary accessible somewhere in your web tree, people will be able to > circumvent .htaccess security by loading files through the PHP parser. A > good way around this is to define doc_root in your php3.ini file to > something other than your top-level DOCUMENT_ROOT. This way you can separate > the part of your web space which uses PHP from the normal part using > .htaccess security. If you do not have any .htaccess restrictions anywhere > on your site you can leave doc_root undefined. >> > > Thank you in advance ! > Eric > > e-mail : awpfr@compuserve.com > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- Derick Rethans JDI Media Solutions H.v.Tussenbroekstraat 1 6952 BL Dieren The Netherlands e-mail: d.rethans@jdimedia.nl http://www.jdimedia.nl/

« previous php.dev (#35650) next »