RE: [PHP] Security problem?
| From: | John Holmes | Date: | Wed, 26 Jun 2002 00:47:12 +0000 |
| Subject: | RE: [PHP] Security problem? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-103863@lists.php.net to get a copy of this message | ||
From: Analysis & Solutions [mailto:danielc@analysisandsolutions.com]
> On Tue, Jun 25, 2002 at 04:08:41PM -0400, Erik Price wrote:
> >
> > This one file is readable only to me and members the
> > "apache" group, and it contains all of the database connection
> > parameters.
>
> I usually run PHP as CGI. My secure files are kept in a directory
that's
> not under the */docroot. Thus, they can't be gotten to through the
web
> server at all. Plus, the secure files are chmoded 600 (which means
they
> can be read/written only by the owner). Thereby, the only user on the
> server who can read them is me.
Who does PHP run as in CGI? Doesn't it run as you, basically? So if you
change all of your files so that only you can access them, PHP still
can, too. Can you still access a file in someone else's directory?
---John Holmes...