Re: PHP Safe Mode Filesystem Circumvention Problem - tested
| From: | Zak Greant | Date: | Wed, 27 Feb 2002 14:38:57 +0000 |
| Subject: | Re: PHP Safe Mode Filesystem Circumvention Problem - tested | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-80454@lists.php.net to get a copy of this message | ||
On Wed, 2002-02-27 at 07:34, Jim Segrave wrote:
> On Wed 27 Feb 2002 (06:31 -0700), Zak Greant wrote:
> > On Wed, 2002-02-27 at 05:40, derick@php.net wrote:
> > > Hello,
> > >
> > > I think it's a bad idea to patch extension for flaws not in PHP itself.
> > > Furthermore, this adds a performance loss to every query. Did you do any
> > > benchmarks with it? Anyway... I still think it's a bad idea, and from what
> > > I've heard Zak is talking with MySQL about this.
>
> Agreed, but when you're selling virtual web-hosting, you have to deal
> with the problems. I think the cost of scanning the SQL queries with a
> pre-compiled regex is unlikely to add a significant cost (in our case
> anyway).
>
> > +1 This is not a PHP problem. We (the PHP we, that is :) can't go
> > around patching PHP for every client lib that we support. That would
> > be hell to deal with for the developers.
>
> I wouldn't suggest that it become part of the distribution.
Heh. Of course, I would have to be rather silly to suggest that a
security patch is not made available because it is not the perfect
solution. :)
Why don't we offer that patch for those who need it now, and then
implement the right solution asap?
Thanks for the patch BTW :)
> > We (the MySQL we, that is :) will have a patch shortly. Additionally,
> > an upcoming release of MySQL will feature an additional permission to
> > control this case.
>
> And this is a much better solution - we'll look forward to that.
>
> --
> Jim Segrave jes@nl.demon.net
--
__ ___ ___ ____ __
/ |/ /_ __/ __/ __ \/ / Zak Greant <zak@mysql.com>
/ /|_/ / // /\ \/ /_/ / /__ MySQL AB, Advocate
/_/ /_/\_, /___/\___\_\___/ Calgary, Canada
<___/ www.mysql.com 403.244.7213