Re: curl_init() is bypassing safe_mode & open_basedir restrictions
| From: | Sterling Hughes | Date: | Sun, 31 Oct 2004 18:46:28 +0000 |
| Subject: | Re: curl_init() is bypassing safe_mode & open_basedir restrictions | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-13645@lists.php.net to get a copy of this message | ||
I still consider adding such things wrong....
-sterling
On Sat, 30 Oct 2004 15:51:12 +0400, Antony Dovgal <tony2001@phpclub.net> wrote:
> On Fri, 29 Oct 2004 16:26:08 +0000
>
>
> Curt Zirzow <curt@php.net> wrote:
>
> > * Thus wrote Antony Dovgal:
> > > On Fri, 29 Oct 2004 01:04:23 -0700
> > > Sterling Hughes <sterling.hughes@gmail.com> wrote:
> > >
> > > > no.... curl does not need to respect php's safemode, adding such
> > > > checks at this level is wrong. people who compile curl, can do so
> > > > without local file access, and this will solve their problem.
> > >
> > > agree, curl doesn't need to respect safemode, but PHP does.
> > > we're talking about PHP's extension, right ?
> >
> > One thing I noticed in some testing was the host part in the
> > file:// url has no meaning so:
> >
> > curl_init('file://whateveryouwant/etc/group');
>
> yup, I see it now.
> I can change the patch to check this too.
>
> Currently I'm waiting for Sterling's response.
> It's senseless to add any additional checks if he still considers
> that adding such things is wrong.
>
>
>
> --
> Wbr,
> Antony Dovgal aka tony2001
> tony2001@phpclub.net || antony@dovgal.com
>
> --
> PHP Internals - PHP Runtime Development Mailing List
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>