Re: PHP 4.0 Bug #7606: Security Hole
| From: | Zeev Suraski | Date: | Fri, 03 Nov 2000 01:03:05 +0000 |
| Subject: | Re: PHP 4.0 Bug #7606: Security Hole | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-36890@lists.php.net to get a copy of this message | ||
There won't be a thorough solution for that in the Apache 1.3 framework. This is not a PHP problem - it's a direct result of the way Apache 1.3 works.
There is a limited solution for this using the safe_mode mechanism, but note that the safe_mode mechanism should not be considered secure, but only as a way of preventing the casual users from reading other people's information.
Zeev
At 02:22 03/11/2000, exothermic@softhome.net wrote:
-- Zeev Suraski <zeev@zend.com> http://www.zend.com/From: exothermic@softhome.netOperating system: LinuxPHP version: 4.0.3pl1 PHP Bug Type: Feature/Change RequestBug description: Security Hole With a multi user system we cannot secure any database driven webapplications that use php. Every file that apache "sees" must be at least readable by every other user. Since php runs as the same user as Apache then that includes the files that contain database logins and passwords. I know there is a way around this using CGI but I would rather not. When will there be a solution to this? -- Edit Bug report at: http://bugs.php.net/?id=7606&edit=1 -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net