RE: [PHP] Security problem?

From: Date: Wed, 26 Jun 2002 00:47:12 +0000
Subject: RE: [PHP] Security problem?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-103863@lists.php.net to get a copy of this message
From: Analysis & Solutions [mailto:danielc@analysisandsolutions.com] > On Tue, Jun 25, 2002 at 04:08:41PM -0400, Erik Price wrote: > > > > This one file is readable only to me and members the > > "apache" group, and it contains all of the database connection > > parameters. > > I usually run PHP as CGI. My secure files are kept in a directory that's > not under the */docroot. Thus, they can't be gotten to through the web > server at all. Plus, the secure files are chmoded 600 (which means they > can be read/written only by the owner). Thereby, the only user on the > server who can read them is me. Who does PHP run as in CGI? Doesn't it run as you, basically? So if you change all of your files so that only you can access them, PHP still can, too. Can you still access a file in someone else's directory? ---John Holmes...

« previous php.general (#103863) next »