Re: [Security-Discuss] Possible PHP hole in Perl?

Ronald Ip <myself-zSWdYiJ/+5RWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <1087221208.16284.5.camel@localhost>
On Mon, 2004-06-14 at 12:04, Bob Puff wrote:
> Hmm, I just tried this with a pretty stock 9.0, as well as a 9.2 install of
> Apache2 and Apache-perl, and the same thing - when browing a .php page on the
> Apache-perl port, I see the original php source.
> 
> If this is a misconfig in the apache-perl config, what part tells it to
> include the php rendering engine?  It certainly appears to be not working by
> default.

The directives to be included into httpd.conf by php is usually found in
/etc/httpd/conf.d/*_mod_php.conf

I'm not exactly sure if apache-perl should be used to serve php pages
alone(?). When I used Apache1, both Apache1 and Apache1-perl, were made
work together by default. Allowing the Apache1 to handle regular pages
and Apache1-perl handle the dynamic stuff. http://www.advx.org/

Therefore, I am quite confused by "when browing a .php page on the
Apache-perl port, I see the original php source."

The Apache-perl port part. How did u access it? Via regular port 80?

Please correct me if I am wrong.

--Ronald

> 
> Bob
> 
> ---------- Original Message -----------
> From: "Ronald Ip" <myself-zSWdYiJ/+5RWk0Htik3J/[email protected]>
> To: security-discuss-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org
> Sent: Mon, 14 Jun 2004 00:41:51 +0800 (SGT)
> Subject: Re: [Security-Discuss] Possible PHP hole in Perl?
> 
> > Hi,
> > 
> > Bob [email protected] said:
> > > Hello,
> > >
> > > Just saw this tonight on one of my boxes.  If I have mod_perl running as a
> > > webserver on port 8200
> > > (the default), and I browse to a .php page, the page is sent without being
> > > rendered by the php
> > > engine - exposing some potentially juicy stuff.  Is this a
> > > misconfiguration on my part, or a
> > > real hole?
> > 
> > It's more like a mis-config. Check that you have the relevent directives
> > required by php in ur httpd.conf.
> > 
> > >
> > > Bob
> > >
> > > Example: http://localhost:8200/myfile.php
> > >
> > >
> > >
> > 
> > -- 
> > Ronald Ip                              myself-zSWdYiJ/+5RWk0Htik3J/[email protected]
> > gpg public key @ http://iphoting.iphoting.com/iphoting.asc
> > Fingerprint: {6A7E AB1E A822 E621 4DEC 11C4 F355 0635 71D7 1151}
> ------- End of Original Message -------
> 
> 
> 
> ______________________________________________________________________
> ____________________________________________________
> Want to buy your Pack or Services from MandrakeSoft? 
> Go to http://www.mandrakestore.com
> Join the Club : http://www.mandrakeclub.com
> ____________________________________________________
--
Ronald Ip                              myself-zSWdYiJ/+5RWk0Htik3J/[email protected]
gpg public key @ http://iphoting.iphoting.com/iphoting.asc
Fingerprint: {6A7E AB1E A822 E621 4DEC 11C4 F355 0635 71D7 1151}
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQBAza3Y81UGNXHXEVERAjukAKCAL4qdzqvwwbmSCHrfhb8FGGBIUgCgwadx
fFEZ99aDbGZCsLjMWvSG3fc=
=oTdE
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.