Re: curl_init() is bypassing safe_mode & open_basedir restrictions
| From: | Derick Rethans | Date: | Fri, 29 Oct 2004 09:13:33 +0000 |
| Subject: | Re: curl_init() is bypassing safe_mode & open_basedir restrictions | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-13592@lists.php.net to get a copy of this message | ||
On Fri, 29 Oct 2004, Klaus Reimer wrote:
> Safe-mode is a feature of PHP so PHP should make sure that this feature
> is working with all functions included in PHP if it's possible to secure
> the function (otherwise the user must disable it). And there is already
> a patch to do it, so it seems to be possible to secure the curl functions.
Myth: Safe mode makes a PHP installation safe.
Wrong! It might make it a bit safer, but there is always a possibility
to work around it. Privilege seperation should be a function of a
webserver, not of a scripting language and therefore we shall not put
hacks in extensions because libraries do not adhere to safe mode. It's
almost certain that one can never put all the necessary checks in the
extension anyway.
Derick
--
Derick Rethans
http://derickrethans.nl | http://ez.no | http://xdebug.org