Re: Fwd: CHINANSL Security Advisory(CSA-200011)
| From: | Ron Chmara | Date: | Sun, 10 Dec 2000 21:52:40 +0000 |
| Subject: | Re: Fwd: CHINANSL Security Advisory(CSA-200011) | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-40773@lists.php.net to get a copy of this message | ||
Zeev Suraski wrote:
> Ok, time to notify bugtraq I guess? Or at least the poster.
> Zeev
> At 22:34 10/12/2000, James Moore wrote:
> >OK I found the key that had to be added in the registry.
> >I tried with 1.3.17 and apache 1.3.6 and COULDNT reproduce this behaviour.
Some observations/thoughts:
1. The actual path to the conf file will likely vary, so their exact reported
string may *not* always work. It would have to have the same path ascent/descent.
2. I would suggest that we use gentle language in the bugtraq correspondance,
after the last go-round with them.
3. We should clarify ASAP that this appears to be limited to PHP/Win, and that
PHP/*nix people can just ignore it. The report seems to indicate that this is
a global PHP issue.
4. Is Apache/win _supposed_ to have a globally readable httd.conf? Shouldn't
the file system perms prevent this exploit?
-Bop
--
Personal: ron@opus1.com, 520-326-6109, http://www.opus1.com/ron/
Work: rchmara@pnsinc.com, 520-546-8993, http://www.pnsinc.com/
The opinions expressed in this email are not neccesarrily those of myself,
my employers, or any of the other little voices in my head.