Bug #13261: Restricting file system access
| From: | mike dot hall at opencube dot co dot uk | Date: | Wed, 12 Sep 2001 09:21:11 +0000 |
| Subject: | Bug #13261: Restricting file system access | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-65811@lists.php.net to get a copy of this message | ||
From: mike.hall@opencube.co.uk
Operating system: Any
PHP version: 4.0.6
PHP Bug Type: Feature/Change Request
Bug description: Restricting file system access
echo
ls /home;
In a virtual host situation, this is very dangerous. On my own host - as an
experiment - I was able to bring back a directory listing of any other site
on the same box. I then did an fread() on his database abstraction script
and read the passwords for his database. Then I logged into his MySQL
database and was free to mess with his site.
It would be EXTREMELY useful to be able to limit the scope of the
filesystem functions so they can only read files inside $DOCUMENT_ROOT.
Although that wouldn't stop me from typing `cat
/home/user/www/database.php`; and getting the same data. This really needs
addressing, guys!
--
Edit bug report at: http://bugs.php.net/?id=13261&edit=1