note 34316 deleted from security.apache by nlopess
| From: | nlopess@php.net | Date: | Tue, 13 Jan 2004 15:18:51 +0000 |
| Subject: | note 34316 deleted from security.apache by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-63444@lists.php.net to get a copy of this message | ||
Note Submitter: spam@digitalphotobox.net
----
Just a little note. I used the open_basedir dirrective, but unfortunatly that doesn't limit
the use of exec. Assuming that you are running as non-safe_mode, this allows a user to load a
script that uses exec('ls -a somepath'); which in turn can be used to walk the whole
filesystem as apache user.
True they still can't view, open or retrieve any of the files that they can see, but they can
still walk the entire file system. You would think there would be a way to limit the scope of exec,
without turning on the whole safe_mode. But is seems like it is all or nothing.