Re: Security feature or bug?
| From: | (Richard Lynch) | Date: | Mon, 03 Jul 2000 23:30:32 +0000 |
| Subject: | Re: Security feature or bug? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-4603@lists.php.net to get a copy of this message | ||
In article <395A0F3A.BBED2539@billtron.com>, bill@billtron.com (bill) wrote:
> I was surprised to find that when I use a PHP page to "serve up" the
> newsletter from outside the web directory tree, it dished up the images
> just fine. They displayed correctly in Netscape 4.7x and IE 5.
If PHP is compiled without SAFE_MODE turned on and/or other settings that
control what files it can read, it can read files outside the web-tree and
do whatever it wants with them, including splatting them at the browser.
This is a feature, not a bug.
The files thusly served up, however, should probably not then be able to
serve up image files outside the web-tree, *UNLESS* you have taken steps
to have PHP be the program retrieving those images: The situation you
describe *COULD* be done with Apache Rewrite rules such that the images
are served up legitimately through PHP.
It would also be easy for you to be seeing old images with the new
Newsletter, don't forget... Are you 100% sure that (possibly "older")
files of those same names do not exist *in* the web-tree as well? [Yeah,
it's a forehead-slapper, but I had to ask.]
Also be sure the images are not in the browser cache.
You can, of course, restrict PHP's power by turning on SAFE_MODE and other
settings as described at http://www.php.net security features page,
at the
loss of some of the flexibility and power, and that would probably alter
the behaviour you are seeing, if it is a bug, since it would be closing
off the HTML file in the first place.
If you are certain that the images are being served up solely because the
HTML next to them made it through, and not through some other legitimate
mechanism, please file a bug report at http://bugs.php.net: At
least,
that's *my* call.
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)