Re: safe_mode for ISPs
| From: | Stanislav Malyshev | Date: | Wed, 24 Nov 1999 09:03:59 +0000 |
| Subject: | Re: safe_mode for ISPs | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-13042@lists.php.net to get a copy of this message | ||
RL>> > a malicious user. We therefore suggest creating a working group that will
RL>> > make a safe_mode that is safe enough for ISPs to use.
RL>>
RL>> Go for it.
RL>>
RL>> Personally I think the best approach from an ISP perspective is to run
RL>> separate server pools each running as the customers' own user id.
Well, but the symlink thing is in fact a bug (or security misfeature), if
it works so. It shouldn't be able to symlink file user doesn't own, or do
something like SymlinkIfOwnersMatch in Apache.
--
Stanislav Malyshev stas@zend.com
+972-50-624945