Re: PHP Safe Mode Filesystem Circumvention Problem - tested

From: Date: Wed, 27 Feb 2002 14:38:57 +0000
Subject: Re: PHP Safe Mode Filesystem Circumvention Problem - tested
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-80454@lists.php.net to get a copy of this message
On Wed, 2002-02-27 at 07:34, Jim Segrave wrote: > On Wed 27 Feb 2002 (06:31 -0700), Zak Greant wrote: > > On Wed, 2002-02-27 at 05:40, derick@php.net wrote: > > > Hello, > > > > > > I think it's a bad idea to patch extension for flaws not in PHP itself. > > > Furthermore, this adds a performance loss to every query. Did you do any > > > benchmarks with it? Anyway... I still think it's a bad idea, and from what > > > I've heard Zak is talking with MySQL about this. > > Agreed, but when you're selling virtual web-hosting, you have to deal > with the problems. I think the cost of scanning the SQL queries with a > pre-compiled regex is unlikely to add a significant cost (in our case > anyway). > > > +1 This is not a PHP problem. We (the PHP we, that is :) can't go > > around patching PHP for every client lib that we support. That would > > be hell to deal with for the developers. > > I wouldn't suggest that it become part of the distribution. Heh. Of course, I would have to be rather silly to suggest that a security patch is not made available because it is not the perfect solution. :) Why don't we offer that patch for those who need it now, and then implement the right solution asap? Thanks for the patch BTW :) > > We (the MySQL we, that is :) will have a patch shortly. Additionally, > > an upcoming release of MySQL will feature an additional permission to > > control this case. > > And this is a much better solution - we'll look forward to that. > > -- > Jim Segrave jes@nl.demon.net -- __ ___ ___ ____ __ / |/ /_ __/ __/ __ \/ / Zak Greant <zak@mysql.com> / /|_/ / // /\ \/ /_/ / /__ MySQL AB, Advocate /_/ /_/\_, /___/\___\_\___/ Calgary, Canada <___/ www.mysql.com 403.244.7213

« previous php.dev (#80454) next »