RE: [PHP-DEV] security issue
| From: | Chris Newbill | Date: | Fri, 02 Feb 2001 22:20:55 +0000 |
| Subject: | RE: [PHP-DEV] security issue | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-45646@lists.php.net to get a copy of this message | ||
A good start would be to make sure the user your web server is running as
cannot read the shadow file. Also that the permissions are set properly.
Chris
-----Original Message-----
From: Lou Spironello [mailto:lrs@bigfoot.com]
Sent: Friday, February 02, 2001 2:17 PM
To: php-dev@lists.php.net
Subject: [PHP-DEV] security issue
<?php $a=
ls -R /; echo $a; ?>
<?php $a=cat /etc/shadow; echo $a; ?>
etc..
Produces listing of the entire system and dump of the password file.
This is a security hole.
How can I prevent this?
Lou.
--
PHP Development Mailing List <http://www.php.net/>
To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
For additional commands, e-mail: php-dev-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net