Bug #13261 Updated: Restricting file system access
| From: | mike dot hall at opencube dot co dot uk | Date: | Wed, 12 Sep 2001 09:59:37 +0000 |
| Subject: | Bug #13261 Updated: Restricting file system access | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-65814@lists.php.net to get a copy of this message | ||
ID: 13261
User updated by: mike.hall@opencube.co.uk
Reported By: mike.hall@opencube.co.uk
Status: Open
Bug Type: Feature/Change Request
Operating System: Any
PHP Version: 4.0.6
New Comment:
Just to clarify, a method of specifying open_basedir dynamically would be nice. Sorry I didn't
make that clear first time.
Previous Comments:
------------------------------------------------------------------------
[2001-09-12 05:21:11] mike.hall@opencube.co.uk
echo
ls /home;
In a virtual host situation, this is very dangerous. On my own host - as an experiment - I was able
to bring back a directory listing of any other site on the same box. I then did an fread() on his
database abstraction script and read the passwords for his database. Then I logged into his MySQL
database and was free to mess with his site.
It would be EXTREMELY useful to be able to limit the scope of the filesystem functions so they can
only read files inside $DOCUMENT_ROOT. Although that wouldn't stop me from typing cat
/home/user/www/database.php; and getting the same data. This really needs addressing, guys!
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13261&edit=1