Bug #13060 Updated: "allow_url_fopen = On" disables safe_mode UID check
| From: | sniper@php.net | Date: | Sat, 20 Oct 2001 23:48:52 +0000 |
| Subject: | Bug #13060 Updated: "allow_url_fopen = On" disables safe_mode UID check | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-68515@lists.php.net to get a copy of this message | ||
ID: 13060
Updated by: sniper
Reported By: admin@kontent.de
Old Status: Open
Status: Closed
Bug Type: *Configuration Issues
Operating System: Linux
PHP Version: 4.0.6
New Comment:
Can not reproduce with PHP 4.1.0 RC1
--Jani
Previous Comments:
------------------------------------------------------------------------
[2001-08-30 11:03:15] admin@kontent.de
When I turn off allow_url_fopen in php.ini the safe_mode UID check seems to be disabled.
With "allow_url_fopen = on" an include("/etc/passwd") returns the following
error:
"The script whose uid is 10000 is not allowed to access /etc/passwd owned by uid 0"
after I've changed the settings to "allow_url_fopen = off" the inclusion works fine,
so there is no way to prevent customers from including external files and local system files.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13060&edit=1