Jump to content

mod_security and php uploadprogress


jake2891

Recommended Posts

Hey, has anyone found an alternative to getting uploadprogress working with apache and mod_security without disabling or changing security settings in mod_security that will compromise the server ? I dont see the point in using this feature if we have to disable security settings on the server ?

 

http://pecl.php.net/bugs/bug.php?id=16954

Bug

 

Description:

------------

No temp file is created when mod_security2 is enabled.

 

Possible cause that I have found is that PHP writes to a different file

name in the user's temp directory when mod_security is enabled compared

to when it is not.

 

Sample temp files created when mod_security is disabled:

phpENU1wg

upt_805677.1259779397.txt

 

where "805677.1259779397" is the UPLOAD_IDENTIFIER.

 

Sample temp files created when mod_security is enabled:

20091202-144325-SxbDWkU8c54AACEoQmIAAAAF-request_body-TgkMtk

 

[2009-12-02 20:06 UTC] blepore at igniteworldwide dot com

 

If this cannot be accomplished, it is worth adding to the documentation

that setting SecRequestBodyAccess to Off will work around the issue

(though leave the site more vulnerable).

 

 

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.