eugene2006
Sep 9th 2006, 10:21 am
Script breaks php security on win2003 XAMPP
This is the script I've checked on my VPS WIN2003 XAMPP
http://php.spb.ru/remview/
http://php.spb.ru/remview/screen_mainwindow.html
http://php.spb.ru/remview/remview_2003_10_23.php
tranlate from rus to eng
http://www.translate.ru/url/tran_url.asp?lang=ru&url=http%3A%2F%2Fphp.spb.ru%2Fremview%2F&direction=re&template=General&cp1=NO&cp2=NO&autotranslate=on&psubmit2.x=47&psubmit2.y=7
and results are horrible ))
*complete* control over entire system - just like it would be a non GUI REMOTE ADMINISTRATOR...
So, how to disallow any script to move beyond it's top/root folder?
For instance if domain name is domen.com and it's placed in c:\vhosts\domen.com
I want any script in this domain not to go upper then / root => c:\vhosts\domen.com\
really need help, because this is a scary stuff
This is the script I've checked on my VPS WIN2003 XAMPP
http://php.spb.ru/remview/
http://php.spb.ru/remview/screen_mainwindow.html
http://php.spb.ru/remview/remview_2003_10_23.php
tranlate from rus to eng
http://www.translate.ru/url/tran_url.asp?lang=ru&url=http%3A%2F%2Fphp.spb.ru%2Fremview%2F&direction=re&template=General&cp1=NO&cp2=NO&autotranslate=on&psubmit2.x=47&psubmit2.y=7
and results are horrible ))
*complete* control over entire system - just like it would be a non GUI REMOTE ADMINISTRATOR...
So, how to disallow any script to move beyond it's top/root folder?
For instance if domain name is domen.com and it's placed in c:\vhosts\domen.com
I want any script in this domain not to go upper then / root => c:\vhosts\domen.com\
really need help, because this is a scary stuff