Re: security in PHP under Apache

From: Date: Wed, 23 May 2001 19:13:00 +0000
Subject: Re: security in PHP under Apache
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-9583@lists.php.net to get a copy of this message
Check out suExec on the Apache website. Also, Apache 2 allows each virtual host to run as a different user - this alleviates some security issues. --zak ----- Original Message ----- From: "Terry Romine" <eatrom@blazing-trails.com> To: "Jonathan Hilgeman" <JHilgeman@ecx.com> Cc: "'Simon R Jones'" <simon@studio24.net>; "PHP-DB (E-mail)" <php-db@lists.php.net> Sent: Wednesday, May 23, 2001 1:12 PM Subject: Re: [PHP-DB] security in PHP under Apache > But how do you set it so a webuser would run sudo? That sounds pretty > dangerous, to me. > > I have a similar situation where I want PHP to create a subdirectory and > set privileges to it based on the login user. I end up having to create > the directory by hand via SSH and then run the php script. > > Terry > > On Wednesday, May 23, 2001, at 12:36 PM, Jonathan Hilgeman wrote: > > > PHP runs via Apache, so it adopts the user that Apache uses, > > essentially. > > You can use a program like sudo to allow them to run certain commands > > on the > > server. > > > > Jonathan > > -- > PHP Database Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net > For additional commands, e-mail: php-db-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.db (#9583) next »