RE: [PHP] Security problem?
| From: | John Holmes | Date: | Wed, 26 Jun 2002 00:53:40 +0000 |
| Subject: | RE: [PHP] Security problem? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-103867@lists.php.net to get a copy of this message | ||
> On Tue, Jun 25, 2002 at 08:47:12PM -0400, John Holmes wrote:
> >
> > Who does PHP run as in CGI? Doesn't it run as you, basically? So if
you
> > change all of your files so that only you can access them, PHP still
> > can, too. Can you still access a file in someone else's directory?
>
> Yep. Good point. But, all file access is controlled by my scripts.
> User input isn't permitted to dictate file system functions. Thus,
> there's no danger.
That's not the problem. On a virtual server with PHP installed as a
module, you can access any file that apache has access to.
Fopen("/path/to/your/directory/and/your/files/file.php");
Now read it and print it to the screen, and get his database password,
etc...
I don't think this applies with PHP as a CGI on a virtual server, does
it? It doesn't matter if your scripts control access, if you include()
it or whatever, that means PHP has access to it. So does another users
PHP script have access to it, too?
---John Holmes...