Re: open_basedir and safe_mode_exec_dir
| From: | Yasuo Ohgaki | Date: | Wed, 17 Jul 2002 06:01:09 +0000 |
| Subject: | Re: open_basedir and safe_mode_exec_dir | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-85973@lists.php.net to get a copy of this message | ||
Yasuo Ohgaki wrote:
> Yasuo Ohgaki wrote:
>
>> Christian Stocker wrote:
>>
>>> another little thingie: the description to open_basedir in the
>>> distributed
>>> php.ini is between all the safe_mode config, therfore maybe a lot of
>>> people don't know, that one can use this whithout safe_mode enabled.
>>>
>>
>> I agree. The directive name should be "safe_mode_open_dasedir"
>> in first place...
>>
>> I added note to php.ini-*
>>
>>
>
> I didn't realized how open_basedir works and sander
> pointed out. Thanks Sander.
>
> Anyway, php_checkuid() does not check open_basedir and
> I immediately noticed user bypass open_basedir with
> pg_lo_import(). I guess there are many functions like
> pg_lo_import().
>
I've commited fixes to pgsql.c, and also
take a look at file.c and it seems sevral functions
do not check safe_mode and open_basedir yet.
(safe_mode/open_basedir could be faked by db command,
etc anyway, though...)
Is there reason why these functions don't check safe_mode
and open_basedir?
I don't have much time to test, so I didn't committed this
patch...
--
Yasuo Ohgaki