Re: why the damn phpinfo() is so talkative? + answers
| From: | Andi Gutmans | Date: | Fri, 20 Oct 2000 11:48:05 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? + answers | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35645@lists.php.net to get a copy of this message | ||
safe_mode needs a revision anyway and I don't like advertising it as being bullet proof. I actually started to centralize stuff with the changes I did a while back in fopen-wrappers but there is still quite a lot of work to be done.
I agree that we should have such a safe programming chapter. You mention a lot of valid points. However, it isn't an all or nothing situation. We can start by writing about the env -i suggestion and extend the chapter more and more, including things like register_globals=off and so on.
Anyway, I'm gone for a short weekend now.
See ya,
Andi
At 12:51 PM 10/20/00 +0200, Kristian Köhntopp wrote:
Andi Gutmans wrote: I think it should be done on the user level like you pointed out below. We could put such a suggestion in the manual (to run with env -i). This is by far not enough. If you are going to put a chapter on safe deployment policies into the manual, you need to differentiate along Windows and Unix systems, and along CGI and module versions of PHP. You'd want to talk about properties and limitations of safe_mode, about Unix process limits such as setrlimit and chroot, about typical additional safeguards for system security such as "env -i", "suexec replaced by sbox, using chroot", about the need to differentiate anonymous root (http docroot) vs. authenticated root (ftp chroot, being one level ABOVE docroot in order to make directories without unauthenticated access available) and the need to store logfiles and configuration files outside of docroot. Also, there should be talk about secure PHP programming, touching not only system level security as above, but also application level security. The section should be talking about control flow analysis, tainted variables, input validation with regexp and other stuff, avoiding register_globals = On in order to facilitate that, writing programs in PHP normal form, event driven programming and validation methods and finally designing secure and ergonomic URLs for your application access... You could, on the other hand, just buy the book by Till and Tobias, which already covers most of this. Kristian -- Kristian Köhntopp, NetUSE AG Siemenswall, D-24107 Kiel Tel: +49 431 386 436 00, Fax: +49 431 386 435 99 Using PHP3? See our web development library at http://phplib.netuse.de/ -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net--- Andi Gutmans <andi@zend.com> http://www.zend.com/