note 28867 deleted from features.safe-mode by cmb

From: Date: Tue, 13 Oct 2020 20:04:39 +0000
Subject: note 28867 deleted from features.safe-mode by cmb
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-215594@lists.php.net to get a copy of this message
Note Submitter: gtg782a at mail dot gatech dot edu ---- zebz: The user would not be able to create a directory outside the namespace where he/she would be able to modify its contents. One can't create a directory that becomes apache-owned unless one owns the parent directory. Another security risk: since files created by apache are owned by apache, a user could call the fputs function and output PHP code to a newly-created file with a .php extension, thus creating an apache-owned PHP script on the server. Executing that apache-owned script would allow the script to work with files in the apache user's namespace, such as logs. A solution would be to force PHP-created files to be owned by the same owner/group as the script that created them. Using open_basedir would be a likely workaround to prevent ascension into uncontrolled areas.

« previous php.notes (#215594) next »