Re: Security feature or bug?

From: Date: Mon, 03 Jul 2000 23:30:32 +0000
Subject: Re: Security feature or bug?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-4603@lists.php.net to get a copy of this message
In article <395A0F3A.BBED2539@billtron.com>, bill@billtron.com (bill) wrote: > I was surprised to find that when I use a PHP page to "serve up" the > newsletter from outside the web directory tree, it dished up the images > just fine. They displayed correctly in Netscape 4.7x and IE 5. If PHP is compiled without SAFE_MODE turned on and/or other settings that control what files it can read, it can read files outside the web-tree and do whatever it wants with them, including splatting them at the browser. This is a feature, not a bug. The files thusly served up, however, should probably not then be able to serve up image files outside the web-tree, *UNLESS* you have taken steps to have PHP be the program retrieving those images: The situation you describe *COULD* be done with Apache Rewrite rules such that the images are served up legitimately through PHP. It would also be easy for you to be seeing old images with the new Newsletter, don't forget... Are you 100% sure that (possibly "older") files of those same names do not exist *in* the web-tree as well? [Yeah, it's a forehead-slapper, but I had to ask.] Also be sure the images are not in the browser cache. You can, of course, restrict PHP's power by turning on SAFE_MODE and other settings as described at http://www.php.net security features page, at the loss of some of the flexibility and power, and that would probably alter the behaviour you are seeing, if it is a bug, since it would be closing off the HTML file in the first place. If you are certain that the images are being served up solely because the HTML next to them made it through, and not through some other legitimate mechanism, please file a bug report at http://bugs.php.net: At least, that's *my* call. -- Richard Lynch | If this was worth $$$ to you, buy a CD US Customer Support Director | from one of the artists listed here: Zend Technologies USA | http://www.L-I-E.com/artists.htm http://www.zend.com | (this has nothing to do with Zend, duh!)

« previous php.general (#4603) next »