Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: [ GLSA 200402-01 ] PHP setting leaks from .htaccess files on virtual hosts
From: Alexander GQ Gerasiov <bugtaq () gq pp ru>
Date: Sun, 8 Feb 2004 00:50:27 +0300

Hello Tim,

7 февраля 2004 г. you wrote:

TY> Synopsis
TY> ========

TY> If the server configuration "php.ini" file has "register_globals = on"
TY> and a request is made to one virtual host (which has "php_admin_flag
TY> register_globals off") and the next request is sent to the another
TY> virtual host (which does not have the setting) through the same apache
TY> child, the setting will persist. This may lead to leaks of global variables.

TY> Background
TY> ==========

TY> PHP is a widely-used general-purpose scripting language that is
TY> especially suited for Web development and can be embedded into HTML.

TY> Description
TY> ===========

TY> If the server configuration "php.ini" file has "register_globals = on"
TY> and a request is made to one virtual host (which has "php_admin_flag
TY> register_globals off") and the next request is sent to the another
TY> virtual host (which does not have the setting) through the same Apache
TY> child, the setting will persist.
I think I had the same problem with safe_mode_include_dir which was set in
<Directory> section of httpd.conf
May be I'm wrong, but problem looks very similar.

-- 
Best regards,
 Alexander GQ Gerasiov <bugtaq () gq pp ru>




  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]