Rozdział 24. Installed as CGI binary

Spis treści
Possible attacks
Case 1: only public files served
Case 2: using --enable-force-cgi-redirect
Case 3: setting doc_root or user_dir
Case 4: PHP parser outside of web tree

Possible attacks

Using PHP as a CGI binary is an option for setups that for some reason do not wish to integrate PHP as a module into server software (like Apache), or will use PHP with different kinds of CGI wrappers to create safe chroot and setuid environments for scripts. This setup usually involves installing executable PHP binary to the web server cgi-bin directory. CERT advisory CA-96.11 recommends against placing any interpreters into cgi-bin. Even if the PHP binary can be used as a standalone interpreter, PHP is designed to prevent the attacks this setup makes possible:

Webmaster DHTML CSS Grafika Flash | Webkatalog | Katalog stron wymagajacy linku zwrotnego | Piano | Feng Shui | Piano | Midi Karaoke | Friendly Page | Piano Grand piano tips tuning lesson Manual PHP | PopUp Blocker | Email address database | Kredyty Gotowkowe | How to Play Piano | Record Guitar Playing on Their Computer Klavier | Piano | Acoustic Guitar Online Guitar Lesson | Digital Piano | Play Piano by Ear | Karaoke | Sennik | Pozycjonowanie | Home Equity Loans | Klavier DJ Wedding | | Software Karaoke | How Old is My Piano | SEO Web Directory Web Advertising Free Advertising Mortgage Mortgage Calculator MortgageLinkor.pl Linkor.pl Linkor.pl Linkor.pl Linkor.pl