Re: curl_init() is bypassing safe_mode & open_basedir restrictions

From: Date: Sun, 31 Oct 2004 18:46:28 +0000
Subject: Re: curl_init() is bypassing safe_mode & open_basedir restrictions
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-13645@lists.php.net to get a copy of this message
I still consider adding such things wrong.... -sterling On Sat, 30 Oct 2004 15:51:12 +0400, Antony Dovgal <tony2001@phpclub.net> wrote: > On Fri, 29 Oct 2004 16:26:08 +0000 > > > Curt Zirzow <curt@php.net> wrote: > > > * Thus wrote Antony Dovgal: > > > On Fri, 29 Oct 2004 01:04:23 -0700 > > > Sterling Hughes <sterling.hughes@gmail.com> wrote: > > > > > > > no.... curl does not need to respect php's safemode, adding such > > > > checks at this level is wrong. people who compile curl, can do so > > > > without local file access, and this will solve their problem. > > > > > > agree, curl doesn't need to respect safemode, but PHP does. > > > we're talking about PHP's extension, right ? > > > > One thing I noticed in some testing was the host part in the > > file:// url has no meaning so: > > > > curl_init('file://whateveryouwant/etc/group'); > > yup, I see it now. > I can change the patch to check this too. > > Currently I'm waiting for Sterling's response. > It's senseless to add any additional checks if he still considers > that adding such things is wrong. > > > > -- > Wbr, > Antony Dovgal aka tony2001 > tony2001@phpclub.net || antony@dovgal.com > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php > >

« previous php.internals (#13645) next »