Doc #65289 [Com]: disable_functions per domain not working
| From: | ben dot rubson at gmail dot com | Date: | Sat, 03 Aug 2013 15:55:10 +0000 |
| Subject: | Doc #65289 [Com]: disable_functions per domain not working | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-10135@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65289&edit=1
ID: 65289
Comment by: ben dot rubson at gmail dot com
Reported by: markku dot niskanen at gmail dot com
Summary: disable_functions per domain not working
Status: Open
Type: Documentation Problem
Package: FPM related
Operating System: Centos 6.2
PHP Version: 5.5.0
Block user comment: N
Private report: N
New Comment:
See summary bug #65386
Previous Comments:
------------------------------------------------------------------------
[2013-07-18 16:11:30] markku dot niskanen at gmail dot com
Actually phpinfo() should NOT show the inactive(?) setting!
It is badly misleading so it is not only about documentation.
Why is it showing it? That fact MUST be classified as a bug because
it is not showing the ACTUAL setting.
It is bit unclear (to me, at least) how the "domain specific"
settings work. If one mentions "global.php.ini only" it will mislead
many users to believe that it is the global php.ini which may contain
domain specific settings as well (like mine did).
That said it also misleads to insecurity: phpinfo() shows the wrong
status and one might believe in it just like I did.
------------------------------------------------------------------------
[2013-07-18 15:14:29] johannes@php.net
The documentation should be made clearer. http://php.net/manual/en/ini.core.php#ini.disable-functions
mentions "php.ini only" while it should be "global php.ini" or something along
the lines. The setting is read during startup only not on every request.
------------------------------------------------------------------------
[2013-07-18 15:07:07] markku dot niskanen at gmail dot com
Description:
------------
NOTE: If this is a feature and not a bug it should be in the documentation.
Using domain specific php.ini disable_functions setting does not work.
Using the settings below I can still run phpinfo(). I can actually see that the
settings should prevent me running it as they are there!
The master value of disable_functions is an empty string. When the setting is
applied as a master value it prevents running the functions correctly.
Tested with Centos 6.2 & Centos 5.4 and PHP 5.5.0 (php-fpm).
Test script:
---------------
# php.ini settings:
# end of php.ini std stuff, host specific stuff starts
[HOST=testdomain.com]
upload_max_filesize=7M
disable_functions=phpinfo,exec,shell_exec,system,passthru
code:
<?php phpinfo();
echo exec('whoami');
Expected result:
----------------
(empty page)
Actual result:
--------------
FULL phpinfo() page plus the user name!
result copied from browser :
disable_functions phpinfo,exec,shell_exec,system,passthru
upload_max_filesize 7M
So the settings are there but not working.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65289&edit=1