note 28867 added to features.safe-mode
| From: | gtg782a at mail dot gatech dot edu | Date: | Sun, 26 Jan 2003 15:14:52 +0000 |
| Subject: | note 28867 added to features.safe-mode | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-42766@lists.php.net to get a copy of this message | ||
zebz: The user would not be able to create a directory outside the namespace where he/she would be
able to modify its contents. One can't create a directory that becomes apache-owned unless one
owns the parent directory.
Another security risk: since files created by apache are owned by apache, a user could call the
fputs function and output PHP code to a newly-created file with a .php extension, thus creating an
apache-owned PHP script on the server. Executing that apache-owned script would allow the script to
work with files in the apache user's namespace, such as logs. A solution would be to force
PHP-created files to be owned by the same owner/group as the script that created them. Using
open_basedir would be a likely workaround to prevent ascension into uncontrolled areas.
--
http://www.php.net/manual/en/features.safe-mode.php
http://master.php.net/manage/user-notes.php?action=edit+28867
http://master.php.net/manage/user-notes.php?action=delete+28867
http://master.php.net/manage/user-notes.php?action=reject+28867