Re: Security Issues
| From: | John W. Holmes | Date: | Tue, 13 Jul 2004 17:23:07 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-35225@lists.php.net to get a copy of this message | ||
Jonathan Haddad wrote:
so I've been doing a little thinking about web server security.. #1. Since all files on the web are 644, what is to stop someone on the same server from copying your files to their own directory? (specifically your database connection info) #2. if a folder if 777, what's to stop someone from writing to that folder?Answer to both questions is a combination of SAFE_MODE and open_basedir restrictions among other things discussed on the manual pages for those functions / features. If those restrictions are not in place, then nothing is stopping someone on the same server to read/write in your filespace with PHP. -- ---John Holmes... Amazon Wishlist: www.amazon.com/o/registry/3BEXC84AB3A5E/ php|architect: The Magazine for PHP Professionals – www.phparch.com