Welcome! Log In Create A New Profile

Advanced

Re: cgi.fix_pathinfo

Rob Schultz
September 23, 2009 07:24PM
You can turn force_redirect off. This setting has no effect on nginx
when using the php as a fastcgi instance. here is more information
http://www.php.net/manual/en/security.cgi-bin.force-redirect.php
It is designed to prevent someone from calling your CGI binary
directly from a url like http://somedomain.com/cgi-bin/php/path/to/script.php
where that would execute PHP directly. Instead this option makes teh
cgi binary require a redirect on the server side.

On Sep 23, 2009, at 1:51 PM, Neves wrote:

> Here I use cgi.fix_pathinfo=0 to enable PATH_INFO
> and cgi.force_redirect=1 for security reasons that I dont understand:
> http://www.php.net/manual/en/ini.core.php#ini.cgi.force-redirect
>
> On Sep 23, 2:49 pm, Ziyad Saeed <myschizobu...@gmail.com> wrote:
>> Whats the recommended setting of these php parameters for nginx
>> server
>> cgi.fix_pathinfo = 1
>> cgi.force_redirect = 0
>
Subject Author Posted

cgi.fix_pathinfo

MySchizoBuddy September 23, 2009 01:56PM

Re: cgi.fix_pathinfo

Neves September 23, 2009 02:56PM

Re: cgi.fix_pathinfo

Rob Schultz September 23, 2009 07:24PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 287
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready