note 34316 added to security.apache

From: Date: Wed, 23 Jul 2003 20:41:24 +0000
Subject: note 34316 added to security.apache
Groups: php.notes 
Request: Send a blank email to php-notes+get-52514@lists.php.net to get a copy of this message
Just a little note. I used the open_basedir dirrective, but unfortunatly that doesn't limit the use of exec. Assuming that you are running as non-safe_mode, this allows a user to load a script that uses exec('ls -a somepath'); which in turn can be used to walk the whole filesystem as apache user. True they still can't view, open or retrieve any of the files that they can see, but they can still walk the entire file system. You would think there would be a way to limit the scope of exec, without turning on the whole safe_mode. But is seems like it is all or nothing. ---- Manual Page -- http://www.php.net/manual/en/security.apache.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+34316 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+34316&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+34316&report=yes

« previous php.notes (#52514) next »