note 28867 added to features.safe-mode

From: Date: Sun, 26 Jan 2003 15:14:52 +0000
Subject: note 28867 added to features.safe-mode
Groups: php.notes 
Request: Send a blank email to php-notes+get-42766@lists.php.net to get a copy of this message
zebz: The user would not be able to create a directory outside the namespace where he/she would be able to modify its contents. One can't create a directory that becomes apache-owned unless one owns the parent directory. Another security risk: since files created by apache are owned by apache, a user could call the fputs function and output PHP code to a newly-created file with a .php extension, thus creating an apache-owned PHP script on the server. Executing that apache-owned script would allow the script to work with files in the apache user's namespace, such as logs. A solution would be to force PHP-created files to be owned by the same owner/group as the script that created them. Using open_basedir would be a likely workaround to prevent ascension into uncontrolled areas. -- http://www.php.net/manual/en/features.safe-mode.php http://master.php.net/manage/user-notes.php?action=edit+28867 http://master.php.net/manage/user-notes.php?action=delete+28867 http://master.php.net/manage/user-notes.php?action=reject+28867

« previous php.notes (#42766) next »