Re: Fwd: CHINANSL Security Advisory(CSA-200011)

From: Date: Sun, 10 Dec 2000 21:52:40 +0000
Subject: Re: Fwd: CHINANSL Security Advisory(CSA-200011)
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-40773@lists.php.net to get a copy of this message
Zeev Suraski wrote: > Ok, time to notify bugtraq I guess? Or at least the poster. > Zeev > At 22:34 10/12/2000, James Moore wrote: > >OK I found the key that had to be added in the registry. > >I tried with 1.3.17 and apache 1.3.6 and COULDNT reproduce this behaviour. Some observations/thoughts: 1. The actual path to the conf file will likely vary, so their exact reported string may *not* always work. It would have to have the same path ascent/descent. 2. I would suggest that we use gentle language in the bugtraq correspondance, after the last go-round with them. 3. We should clarify ASAP that this appears to be limited to PHP/Win, and that PHP/*nix people can just ignore it. The report seems to indicate that this is a global PHP issue. 4. Is Apache/win _supposed_ to have a globally readable httd.conf? Shouldn't the file system perms prevent this exploit? -Bop -- Personal: ron@opus1.com, 520-326-6109, http://www.opus1.com/ron/ Work: rchmara@pnsinc.com, 520-546-8993, http://www.pnsinc.com/ The opinions expressed in this email are not neccesarrily those of myself, my employers, or any of the other little voices in my head.

« previous php.dev (#40773) next »