Bug #13207 Updated: open_basedir not restricting file access properly
| From: | rasmus@php.net | Date: | Sat, 08 Sep 2001 01:25:52 +0000 |
| Subject: | Bug #13207 Updated: open_basedir not restricting file access properly | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-65403@lists.php.net to get a copy of this message | ||
ID: 13207
Updated by: rasmus
Reported By: jedi@tstonramp.com
Status: Open
Bug Type: IIS related
Operating System: NT 4.0
PHP Version: 4.0.6
New Comment:
You don't have open_basedir enabled. The error message from an open_basedir restriction is not
"permission denied". Does your phpinfo() output tell you that open_basedir is in effect?
Previous Comments:
------------------------------------------------------------------------
[2001-09-07 19:09:40] jedi@tstonramp.com
Script is as follows:
mkdir("/test",0700);
phpinfo();
I'm running IIS 4.0 on NT 4.0 SP6. This code is running in my web servers default web site. I
AM doing Virtual Web hosting using Host Header method, not multiple IPs. The anonymous web user for
the virtual web server in question let's say is called: anon
When the script is run and anon is *denied* permissions to C:\ the following error is generated:
Warning: MkDir failed (Permission denied) in C:\InetPub\wwwroot\php\test.php on line 2
and PHPInfo displays open_basedir as being: C:\inetpub
(This is good.)
When I go in and grant user anon "Change" privileges to C:\ (I do NOT apply to all
subdirectories) and re-run the script then:
I get NO error message and __THE DIRECTORY IS CREATED__ as C:\test
This is bad. VERY bad. I need to be able to rely on open_basedir preventing __ANY__ file access
outside of C:\inetpub.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13207&edit=1