Query about safe mode on 3.0.2a
| From: | Rodney McDuff | Date: | Mon, 10 Aug 1998 05:34:09 +0000 |
| Subject: | Query about safe mode on 3.0.2a | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-65@lists.php.net to get a copy of this message | ||
Hi
I was experiment with safe mode on 3.0.2a (Apache-1.3.0 on DU4.0) and found
something unexpected. I was working on a script to create a new file in a
directory owned by the script and writable by the web server (running under
http). I found that I could create a file even though the directory was owned
as someone other than the script owner (but still writable by the web server).
I tracked this down to php3_fopen_wrapper routine in fopen-wrappers.c where a
call was made to _php3_checkuid(path, 1). My query is that this should be
_php3_checkuid(path, 2). The documentataion for php3_checkuid is
* This function has four modes:
*
* 0 - return invalid (0) if file does not exist
* 1 - return valid (1) if file does not exist
* 2 - if file does not exist, check directory
* 3 - only check directory (needed for mkdir)
and 2 fits the bill. Moreover other instances of _php3_checkuid in
fopen-wrappers.c (php3_fopen_with_path for instance) use mode 2 as well.
Any input on this would be appreciated.
PS. Making the modification in php3_fopen_wrapper work for me. ie I can only
create a file in a directory owned my the script.
PPS there's a number of other places where I think the _php3_checkuid mode
should be 2 as well.
*** fopen-wrappers.c Mon Aug 10 15:29:42 1998
--- fopen-wrappers.c.orig Mon Aug 10 15:29:21 1998
***************
*** 108,114 ****
if (options & USE_PATH && php3_ini.include_path != NULL) {
return php3_fopen_with_path(path, mode, php3_ini.include_path,
NULL);
} else {
! if (options & ENFORCE_SAFE_MODE && php3_ini.safe_mode &&
(!_php3_checkuid(path, 2))) {
php3_error(E_WARNING, "SAFE MODE Restriction in
effect. Invalid owner of file to be read.");
return NULL;
}
--- 108,114 ----
if (options & USE_PATH && php3_ini.include_path != NULL) {
return php3_fopen_with_path(path, mode, php3_ini.include_path,
NULL);
} else {
! if (options & ENFORCE_SAFE_MODE && php3_ini.safe_mode &&
(!_php3_checkuid(path, 1))) {
php3_error(E_WARNING, "SAFE MODE Restriction in
effect. Invalid owner of file to be read.");
return NULL;
}
--
+-----------------+------------------------------------------+
| _ ^ _ | Dr. Rodney McDuff |
| |\ /|\ /| | Network Development, Prentice Centre |
| \ | / | The University of Queensland |
| \ | / | St. Lucia, Brisbane |
| \|/ | Queensland, Australia. 4072. |
|<-------+------->| TELEPHONE: +61 7 3365 4794 |
| /|\ | FACSIMILE: +61 7 3365 4477 |
| / | \ | EMAIL: mcduff@prentice.uq.edu.au |
| / | \ | |
| |/ \|/ \| | Ex ignorantia ad sapientiam |
| - v - | Ex luce ad tenebras |
+-----------------+------------------------------------------+
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net