note 34316 deleted from security.apache by nlopess

From: Date: Tue, 13 Jan 2004 15:18:51 +0000
Subject: note 34316 deleted from security.apache by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-63444@lists.php.net to get a copy of this message
Note Submitter: spam@digitalphotobox.net ---- Just a little note. I used the open_basedir dirrective, but unfortunatly that doesn't limit the use of exec. Assuming that you are running as non-safe_mode, this allows a user to load a script that uses exec('ls -a somepath'); which in turn can be used to walk the whole filesystem as apache user. True they still can't view, open or retrieve any of the files that they can see, but they can still walk the entire file system. You would think there would be a way to limit the scope of exec, without turning on the whole safe_mode. But is seems like it is all or nothing.

« previous php.notes (#63444) next »