Re: uhm.. *swallows*.. security thingy?
| From: | Zeev Suraski | Date: | Wed, 12 Dec 2001 23:03:41 +0000 |
| Subject: | Re: uhm.. *swallows*.. security thingy? | ||
| References: | 1 2 3 4 5 6 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-73413@lists.php.net to get a copy of this message | ||
At 11:20 12/12/2001, Teodor Cimpoesu wrote:
[rant++] I don't think it's a problem for a user to make a copy of the php binary somewhere in any of those dirs, where the cwd at runtime is a writeable dir...Well, if he can run arbitrary files from his own directories, you're screwed anyway, much more than any PHP related security exploit :) The directories from which the server agrees to run binaries are quite limited. Zeev