Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:27494 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 58446 invoked by uid 1010); 17 Jan 2007 01:49:45 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 58431 invoked from network); 17 Jan 2007 01:49:45 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 17 Jan 2007 01:49:45 -0000 Authentication-Results: pb1.pair.com header.from=stas@zend.com; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=stas@zend.com; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain zend.com designates 212.25.124.162 as permitted sender) X-PHP-List-Original-Sender: stas@zend.com X-Host-Fingerprint: 212.25.124.162 mail.zend.com Linux 2.5 (sometimes 2.4) (4) Received: from [212.25.124.162] ([212.25.124.162:23995] helo=mail.zend.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 85/C6-05231-7B08DA54 for ; Tue, 16 Jan 2007 20:49:45 -0500 Received: (qmail 6228 invoked from network); 17 Jan 2007 01:48:02 -0000 Received: from office.zend.office (HELO ?127.0.0.1?) (192.168.16.109) by internal.zend.office with SMTP; 17 Jan 2007 01:48:02 -0000 Message-ID: <45AD8036.1050202@zend.com> Date: Tue, 16 Jan 2007 17:47:34 -0800 Organization: Zend Technologies User-Agent: Thunderbird 2.0b1 (Windows/20061206) MIME-Version: 1.0 To: Gregory Beaver CC: Stefan Esser , Marcus Boerger , "internals@lists.php.net" References: <45A8FC49.7050909@hardened-php.net> <45A90809.3050008@lerdorf.com> <45A91002.8020607@hardened-php.net> <526994769.20070113181330@marcus-boerger.de> <45AA116F.7020109@hardened-php.net> <45AA961D.4090401@php.net> <45AD416E.4020502@zend.com> <45AD76BF.6050305@chiaraquartet.net> In-Reply-To: <45AD76BF.6050305@chiaraquartet.net> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [PHP-DEV] Comments on PHP security From: stas@zend.com (Stanislav Malyshev) > Actually, the solution I was envisioning would not allow any access to > fsockopen() or other remote streams access things inside a user stream > wrapper. Are you sure you can evaluate ALL engine functions that allow accessing remote data? Looks dangerously like safe mode... -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/