Securing PHP functions and abilties with Virtual Hosts
| From: | Siggy | Date: | Tue, 02 Oct 2001 22:10:19 +0000 |
| Subject: | Securing PHP functions and abilties with Virtual Hosts | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-12941@lists.php.net to get a copy of this message | ||
Hi,
I run a webhosting service and am about to offer MySQL to .PHP customers; and
am wondering if there is a way with in Apache Virtual Host directives to ...
- enable/disable safe mode (we have some scripts on our https server and we
need to be able to set up new websites etc, but we want to secure all
customer sites, or is it better to make the owner of such scripts root, so
the less exploits occur?)
- enable/disable specific functions it would be nice to disable mysql_*
functions, so even if they got someone's password to a database, they can't
exactly do a whole lot! :) Perhaps that could be done by a 'use this php.ini'
directive?
- also, what is the directive to disable the php enging for a site?
"php_engine off" wasn't understood by Apache.
Is this possible without running multiple httpd daemons etc?
Running Redhat 7.1, Apache 1.3.19/PHP 4.0.4.
Any suggestions in improving security as a whole is appreciated.
Thanks heaps,
Sigurd Magnusson