diff options
| -rw-r--r-- | execute.c | 8 | ||||
| -rw-r--r-- | tests/include/include_constant.phpt | 2 | ||||
| -rw-r--r-- | tests/include/include_once_constant.phpt | 2 | ||||
| -rw-r--r-- | tests/include/include_once_tmpvar.phpt | 2 | ||||
| -rw-r--r-- | tests/include/include_once_var.phpt | 2 | ||||
| -rw-r--r-- | tests/include/include_tmpvar.phpt | 2 | ||||
| -rw-r--r-- | tests/include/include_var.phpt | 2 | ||||
| -rw-r--r-- | tests/include/require_constant.phpt | 2 | ||||
| -rw-r--r-- | tests/include/require_once_constant.phpt | 2 | ||||
| -rw-r--r-- | tests/include/require_once_tmpvar.phpt | 2 | ||||
| -rw-r--r-- | tests/include/require_once_var.phpt | 2 | ||||
| -rw-r--r-- | tests/include/require_tmpvar.phpt | 2 | ||||
| -rw-r--r-- | tests/include/require_var.phpt | 2 |
13 files changed, 16 insertions, 16 deletions
| @@ -299,12 +299,12 @@ static zend_bool suhosin_zend_open(const char *filename, zend_file_handle *fh) | |||
| 299 | break; | 299 | break; |
| 300 | 300 | ||
| 301 | case SUHOSIN_CODE_TYPE_BLACKURL: | 301 | case SUHOSIN_CODE_TYPE_BLACKURL: |
| 302 | suhosin_log(S_INCLUDE, "Include filename ('%s') is an URL that is forbidden by the blacklist", filename); | 302 | suhosin_log(S_INCLUDE, "Include filename ('%s') is a URL that is forbidden by the blacklist", filename); |
| 303 | suhosin_bailout(TSRMLS_C); | 303 | suhosin_bailout(TSRMLS_C); |
| 304 | break; | 304 | break; |
| 305 | 305 | ||
| 306 | case SUHOSIN_CODE_TYPE_BADURL: | 306 | case SUHOSIN_CODE_TYPE_BADURL: |
| 307 | suhosin_log(S_INCLUDE, "Include filename ('%s') is an URL that is not allowed", filename); | 307 | suhosin_log(S_INCLUDE, "Include filename ('%s') is a URL that is not allowed", filename); |
| 308 | suhosin_bailout(TSRMLS_C); | 308 | suhosin_bailout(TSRMLS_C); |
| 309 | break; | 309 | break; |
| 310 | 310 | ||
| @@ -607,12 +607,12 @@ not_evaled_code: | |||
| 607 | break; | 607 | break; |
| 608 | 608 | ||
| 609 | case SUHOSIN_CODE_TYPE_BLACKURL: | 609 | case SUHOSIN_CODE_TYPE_BLACKURL: |
| 610 | suhosin_log(S_INCLUDE|S_GETCALLER, "Include filename ('%s') is an URL that is forbidden by the blacklist", op_array->filename); | 610 | suhosin_log(S_INCLUDE|S_GETCALLER, "Include filename ('%s') is a URL that is forbidden by the blacklist", op_array->filename); |
| 611 | suhosin_bailout(TSRMLS_C); | 611 | suhosin_bailout(TSRMLS_C); |
| 612 | break; | 612 | break; |
| 613 | 613 | ||
| 614 | case SUHOSIN_CODE_TYPE_BADURL: | 614 | case SUHOSIN_CODE_TYPE_BADURL: |
| 615 | suhosin_log(S_INCLUDE|S_GETCALLER, "Include filename ('%s') is an URL that is not allowed", op_array->filename); | 615 | suhosin_log(S_INCLUDE|S_GETCALLER, "Include filename ('%s') is a URL that is not allowed", op_array->filename); |
| 616 | suhosin_bailout(TSRMLS_C); | 616 | suhosin_bailout(TSRMLS_C); |
| 617 | break; | 617 | break; |
| 618 | 618 | ||
diff --git a/tests/include/include_constant.phpt b/tests/include/include_constant.phpt index 180aa69..9fdb5ac 100644 --- a/tests/include/include_constant.phpt +++ b/tests/include/include_constant.phpt | |||
| @@ -14,4 +14,4 @@ suhosin.executor.include.blacklist= | |||
| 14 | include "http://127.0.0.1/"; | 14 | include "http://127.0.0.1/"; |
| 15 | ?> | 15 | ?> |
| 16 | --EXPECTF-- | 16 | --EXPECTF-- |
| 17 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) | 17 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) |
diff --git a/tests/include/include_once_constant.phpt b/tests/include/include_once_constant.phpt index 3faac33..66823cd 100644 --- a/tests/include/include_once_constant.phpt +++ b/tests/include/include_once_constant.phpt | |||
| @@ -14,4 +14,4 @@ suhosin.executor.include.blacklist= | |||
| 14 | include_once "http://127.0.0.1/"; | 14 | include_once "http://127.0.0.1/"; |
| 15 | ?> | 15 | ?> |
| 16 | --EXPECTF-- | 16 | --EXPECTF-- |
| 17 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) | 17 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) |
diff --git a/tests/include/include_once_tmpvar.phpt b/tests/include/include_once_tmpvar.phpt index 1f94c5a..4206893 100644 --- a/tests/include/include_once_tmpvar.phpt +++ b/tests/include/include_once_tmpvar.phpt | |||
| @@ -16,4 +16,4 @@ suhosin.executor.include.blacklist= | |||
| 16 | include_once $var.$app; | 16 | include_once $var.$app; |
| 17 | ?> | 17 | ?> |
| 18 | --EXPECTF-- | 18 | --EXPECTF-- |
| 19 | ALERT - Include filename ('http://127.0.0.1/?') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) | 19 | ALERT - Include filename ('http://127.0.0.1/?') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) |
diff --git a/tests/include/include_once_var.phpt b/tests/include/include_once_var.phpt index bf38377..3ba3ff7 100644 --- a/tests/include/include_once_var.phpt +++ b/tests/include/include_once_var.phpt | |||
| @@ -15,4 +15,4 @@ suhosin.executor.include.blacklist= | |||
| 15 | include_once $var; | 15 | include_once $var; |
| 16 | ?> | 16 | ?> |
| 17 | --EXPECTF-- | 17 | --EXPECTF-- |
| 18 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) | 18 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) |
diff --git a/tests/include/include_tmpvar.phpt b/tests/include/include_tmpvar.phpt index 8ad26d7..31d2f0f 100644 --- a/tests/include/include_tmpvar.phpt +++ b/tests/include/include_tmpvar.phpt | |||
| @@ -16,4 +16,4 @@ suhosin.executor.include.blacklist= | |||
| 16 | include $var.$app; | 16 | include $var.$app; |
| 17 | ?> | 17 | ?> |
| 18 | --EXPECTF-- | 18 | --EXPECTF-- |
| 19 | ALERT - Include filename ('http://127.0.0.1/?') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) | 19 | ALERT - Include filename ('http://127.0.0.1/?') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) |
diff --git a/tests/include/include_var.phpt b/tests/include/include_var.phpt index 7431240..598c093 100644 --- a/tests/include/include_var.phpt +++ b/tests/include/include_var.phpt | |||
| @@ -15,4 +15,4 @@ suhosin.executor.include.blacklist= | |||
| 15 | include $var; | 15 | include $var; |
| 16 | ?> | 16 | ?> |
| 17 | --EXPECTF-- | 17 | --EXPECTF-- |
| 18 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) | 18 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) |
diff --git a/tests/include/require_constant.phpt b/tests/include/require_constant.phpt index 6ee79fb..358d69d 100644 --- a/tests/include/require_constant.phpt +++ b/tests/include/require_constant.phpt | |||
| @@ -14,4 +14,4 @@ suhosin.executor.include.blacklist= | |||
| 14 | require "http://127.0.0.1/"; | 14 | require "http://127.0.0.1/"; |
| 15 | ?> | 15 | ?> |
| 16 | --EXPECTF-- | 16 | --EXPECTF-- |
| 17 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) | 17 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) |
diff --git a/tests/include/require_once_constant.phpt b/tests/include/require_once_constant.phpt index 43c69c8..699720a 100644 --- a/tests/include/require_once_constant.phpt +++ b/tests/include/require_once_constant.phpt | |||
| @@ -14,4 +14,4 @@ suhosin.executor.include.blacklist= | |||
| 14 | require_once "http://127.0.0.1/"; | 14 | require_once "http://127.0.0.1/"; |
| 15 | ?> | 15 | ?> |
| 16 | --EXPECTF-- | 16 | --EXPECTF-- |
| 17 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) | 17 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 2) |
diff --git a/tests/include/require_once_tmpvar.phpt b/tests/include/require_once_tmpvar.phpt index 2be24b2..956b563 100644 --- a/tests/include/require_once_tmpvar.phpt +++ b/tests/include/require_once_tmpvar.phpt | |||
| @@ -16,4 +16,4 @@ suhosin.executor.include.blacklist= | |||
| 16 | require_once $var.$app; | 16 | require_once $var.$app; |
| 17 | ?> | 17 | ?> |
| 18 | --EXPECTF-- | 18 | --EXPECTF-- |
| 19 | ALERT - Include filename ('http://127.0.0.1/?') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) | 19 | ALERT - Include filename ('http://127.0.0.1/?') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) |
diff --git a/tests/include/require_once_var.phpt b/tests/include/require_once_var.phpt index b3857f5..7a2e813 100644 --- a/tests/include/require_once_var.phpt +++ b/tests/include/require_once_var.phpt | |||
| @@ -15,4 +15,4 @@ suhosin.executor.include.blacklist= | |||
| 15 | require_once $var; | 15 | require_once $var; |
| 16 | ?> | 16 | ?> |
| 17 | --EXPECTF-- | 17 | --EXPECTF-- |
| 18 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) | 18 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) |
diff --git a/tests/include/require_tmpvar.phpt b/tests/include/require_tmpvar.phpt index d411067..e0b504f 100644 --- a/tests/include/require_tmpvar.phpt +++ b/tests/include/require_tmpvar.phpt | |||
| @@ -16,4 +16,4 @@ suhosin.executor.include.blacklist= | |||
| 16 | require $var.$app; | 16 | require $var.$app; |
| 17 | ?> | 17 | ?> |
| 18 | --EXPECTF-- | 18 | --EXPECTF-- |
| 19 | ALERT - Include filename ('http://127.0.0.1/?') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) | 19 | ALERT - Include filename ('http://127.0.0.1/?') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 4) |
diff --git a/tests/include/require_var.phpt b/tests/include/require_var.phpt index 20468d4..3ff9745 100644 --- a/tests/include/require_var.phpt +++ b/tests/include/require_var.phpt | |||
| @@ -15,4 +15,4 @@ suhosin.executor.include.blacklist= | |||
| 15 | require $var; | 15 | require $var; |
| 16 | ?> | 16 | ?> |
| 17 | --EXPECTF-- | 17 | --EXPECTF-- |
| 18 | ALERT - Include filename ('http://127.0.0.1/') is an URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) | 18 | ALERT - Include filename ('http://127.0.0.1/') is a URL that is not allowed (attacker 'REMOTE_ADDR not set', file '%s', line 3) |
