Welcome! Log In Create A New Profile

Advanced

Re: Possible widespread PHP configuration issue - security risk

Adam Younce
August 27, 2010 01:16PM
Gentlemen, please. Let's keep this civil.

The simplest solution to the problem presented would be to change the wiki to encourage users to set their upload directory to a location not served by nginx (and thus not executable by PHP). This is *entirely* a PHP configuration issue.

There are still dangers depending on what the application does with the uploaded files, but those exist no matter what. Making the change to the documentation to encourage this best practice should suffice for us.

--

Adam Younce
ayounce@ripcord.net

On Aug 27, 2010, at 10:58 AM, Ed W wrote:

> On 27/08/2010 17:32, Nuno Magalh?es wrote:
>>> I said to stop complaining about the content of the Wiki and feel
>>> free to fix it. You seem to have all the answers.
>>
>>> Oh fuck off you twit.
>> Gee, you're so mature.
>
> How is your post advancing the solution?
>
> How about you avoid quoting out of context parts of my message and focus
> on the rest of that message?
>
> Regards
>
> Ed W


_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
Subject Author Posted

Re: Possible widespread PHP configuration issue - security risk

Adam Younce August 27, 2010 01:16PM

Re: Possible widespread PHP configuration issue - security risk

Ed W August 27, 2010 01:32PM

Re: Possible widespread PHP configuration issue - security risk

Cliff Wells August 27, 2010 01:36PM

Re: Possible widespread PHP configuration issue - security risk

Ed W August 27, 2010 01:46PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 165
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready