PHP 4.0 Bug #7606 Updated: Security Hole
| From: | joey@php.net | Date: | Fri, 03 Nov 2000 22:40:15 +0000 |
| Subject: | PHP 4.0 Bug #7606 Updated: Security Hole | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-37037@lists.php.net to get a copy of this message | ||
ID: 7606
Updated by: joey
Reported By: exothermic@softhome.net
Status: Closed
Bug Type: Feature/Change Request
Assigned To:
Comments:
Zeev replied to the dev list:
There won't be a thorough solution for that in the Apache 1.3
framework. This is not a PHP problem - it's a direct result of the way
Apache 1.3 works.
There is a limited solution for this using the safe_mode mechanism, but
note that the safe_mode mechanism should not be considered secure, but only
as a way of preventing the casual users from reading other people's
information.
Previous Comments:
---------------------------------------------------------------------------
[2000-11-02 19:22:51] exothermic@softhome.net
With a multi user system we cannot secure any database driven webapplications that use php. Every
file that apache "sees" must be at least readable by every other user. Since php runs as
the same user as Apache then that includes the files that contain database logins and passwords. I
know there is a way around this using CGI but I would rather not. When will there be a solution to
this?
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=7606