Re: Re: Safe Mode & open_basedir
| From: | Yasuo Ohgaki | Date: | Thu, 08 Aug 2002 08:53:23 +0000 |
| Subject: | Re: Re: Safe Mode & open_basedir | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-86629@lists.php.net to get a copy of this message | ||
Stefan Esser wrote:
I'm well aware of streams is checking safe mode. Are you sure all wrappers are checking open_basedir, too? Then we can get rid of some open_basedir checks. file.c was inconsistent before my patch anyway. And I didn't check if wrapper checks open_basedir at that time. Even if I think these checks are better to be preformed at the bebinnging of function calls, we don't need to check it multiple times. Anyway, why didn't tell me when I committed it? Let me know, if you are sure, I'll clean up at leat my commits if it's still there.BTW, there should be many functions that do not check safe_mode/open_basedir. With 1 minuite search, I fixed(added) sevral open_basedir checks recently. sofemode/open_basedir can be bypassed easily. We don't have to put more effort for barely working solution...Your open_basedir/safe_mode patches were completely bogus because the streams check open_basedir and safe_mode themself.
And it is not true that safe_mode is a barely working solution. The only problem is that php has no control over 3rd party libs that allow access to other files.I'm not saying it's useless even if it may sounded so Too many people believe safe_mode and open_basedir is _secure_ under shared environment. That's why I'm advertising ;) -- Yasuo Ohgaki