Re: curl_init() is bypassing safe_mode & open_basedir restrictions
| From: | Curt Zirzow | Date: | Fri, 29 Oct 2004 16:26:08 +0000 |
| Subject: | Re: curl_init() is bypassing safe_mode & open_basedir restrictions | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-13596@lists.php.net to get a copy of this message | ||
* Thus wrote Antony Dovgal:
> On Fri, 29 Oct 2004 01:04:23 -0700
> Sterling Hughes <sterling.hughes@gmail.com> wrote:
>
> > no.... curl does not need to respect php's safemode, adding such
> > checks at this level is wrong. people who compile curl, can do so
> > without local file access, and this will solve their problem.
>
> agree, curl doesn't need to respect safemode, but PHP does.
> we're talking about PHP's extension, right ?
One thing I noticed in some testing was the host part in the
file:// url has no meaning so:
curl_init('file://whateveryouwant/etc/group');
Works fine.
Curt
--
First, let me assure you that this is not one of those shady pyramid schemes
you've been hearing about. No, sir. Our model is the trapezoid!