3 ms·
> as evidenced by the (former, hopefully) widespread use of exploitable php calls Could someone elaborate on what this is referring to?
by lonnyk 12y ago
> as evidenced by the (former, hopefully) widespread use of exploitable php calls
Could someone elaborate on what this is referring to?
- meowface 12y agoRead through https://nealpoole.com/blog/2011/04/setting-up-php-fastcgi-and-nginx-dont-trust-the-tutorials-check-your-configuration/ https://nealpoole.com/blog/2011/04/setting-up-php-fastcgi-an...
- makomk 12y agoThat's not really nginx's fault, its behaviour is quite sensible. The main problem is that PHP does some poorly-documented magic behind the scenes[1] that modifies the information nginx gives it in a way that causes security issues. The solution is not to do that; if you really need the path-splitting functionality that cgi.fix_pathinfo provides, it's better and safer to set fastcgi_split_path_info in the nginx configuration instead. [1] http://php.net/manual/en/ini.core.php#ini.cgi.fix-pathinfo http://php.net/manual/en/ini.core.php#ini.cgi.fix-pathinfo - the docs on cgi.fix_pathinfo don't mention that it affects which PHP file gets executed at all.