RE: [PHP-DEV] security issue

From: Date: Fri, 02 Feb 2001 22:20:55 +0000
Subject: RE: [PHP-DEV] security issue
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-45646@lists.php.net to get a copy of this message
A good start would be to make sure the user your web server is running as cannot read the shadow file. Also that the permissions are set properly. Chris -----Original Message----- From: Lou Spironello [mailto:lrs@bigfoot.com] Sent: Friday, February 02, 2001 2:17 PM To: php-dev@lists.php.net Subject: [PHP-DEV] security issue <?php $a=ls -R /; echo $a; ?> <?php $a=cat /etc/shadow; echo $a; ?> etc.. Produces listing of the entire system and dump of the password file. This is a security hole. How can I prevent this? Lou. -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#45646) next »