List Info

Thread: note 61716 added to install.windows.iis




note 61716 added to install.windows.iis
user name
2006-02-10 08:06:05
Security Alert! PHP CGI cannot be accessed directly. 
This PHP CGI binary was compiled with force-cgi-redirect
enabled. This means that a page will only be served up if
the REDIRECT_STATUS CGI variable is set. This variable is
set, for example, by Apache's Action directive redirect. 

You may disable this restriction by recompiling the PHP
binary with the --disable-force-cgi-redirect switch. If you
do this and you have your PHP CGI binary accessible
somewhere in your web tree, people will be able to
circumvent .htaccess security by loading files through the
PHP parser. A good way around this is to define doc_root in
your php.ini file to something other than your top-level
DOCUMENT_ROOT. This way you can separate the part of your
web space which uses PHP from the normal part using
.htaccess security. If you do not have any .htaccess
restrictions anywhere on your site you can leave doc_root
undefined. If you are running IIS, you may safely set
cgi.force_redirect=0 in php.ini.
----
Server IP: 61.129.33.155
Probable Submitter: 210.79.247.225
----
Manual Page -- 
http://www.php.net/manual/en/install.windows.iis.php
Edit        -- http://master.php.net/manage/user-notes.php?action=
edit+61716
Delete: added to the manual -- htt
p://master.php.net/manage/user-notes.php?action=delete+61716
&report=yes&reason=added+to+the+manual
Delete: bad code            -- http://master.
php.net/manage/user-notes.php?action=delete+61716&report
=yes&reason=bad+code
Delete: spam                -- http://master.php.
net/manage/user-notes.php?action=delete+61716&report=yes
&reason=spam
Delete: useless             -- http://master.p
hp.net/manage/user-notes.php?action=delete+61716&report=
yes&reason=useless
Delete: non-english         -- http://mast
er.php.net/manage/user-notes.php?action=delete+61716&rep
ort=yes&reason=non-english
Delete: already in docs     -- http://
master.php.net/manage/user-notes.php?action=delete+61716&
;report=yes&reason=already+in+docs
Delete: other reasons       -- http://master.php.net/manage/user-
notes.php?action=delete+61716&report=yes
Reject      -- http://master.php.net/manage/user-
notes.php?action=reject+61716&report=yes
Search      -- http://ma
ster.php.net/manage/user-notes.php

-- 
PHP Notes Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub
.php

note 61716 deleted from install.windows.iis by betz
user name
2006-02-10 10:31:07
Note Submitter:  

----

Security Alert! PHP CGI cannot be accessed directly. 
This PHP CGI binary was compiled with force-cgi-redirect
enabled. This means that a page will only be served up if
the REDIRECT_STATUS CGI variable is set. This variable is
set, for example, by Apache's Action directive redirect. 

You may disable this restriction by recompiling the PHP
binary with the --disable-force-cgi-redirect switch. If you
do this and you have your PHP CGI binary accessible
somewhere in your web tree, people will be able to
circumvent .htaccess security by loading files through the
PHP parser. A good way around this is to define doc_root in
your php.ini file to something other than your top-level
DOCUMENT_ROOT. This way you can separate the part of your
web space which uses PHP from the normal part using
.htaccess security. If you do not have any .htaccess
restrictions anywhere on your site you can leave doc_root
undefined. If you are running IIS, you may safely set
cgi.force_redirect=0 in php.ini.

-- 
PHP Notes Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub
.php

[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )