Re: Security problem?

From: Date: Wed, 26 Jun 2002 01:16:18 +0000
Subject: Re: Security problem?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-103870@lists.php.net to get a copy of this message
> On Tue, Jun 25, 2002 at 08:53:40PM -0400, John Holmes wrote: > > > > I don't think this applies with PHP as a CGI on a virtual server, does > > it? It doesn't matter if your scripts control access, if you include() > > it or whatever, that means PHP has access to it. So does another users > > PHP script have access to it, too? > > Huh? Not that I know of. PHP as CGI is running as my user id. For other > people on the server, PHP runs as their user id. Thus, only my scripts > have access to my files if I give them 600 permissions. That is only the case if your server is set up to use SuExec or something similar. By default if you simply run PHP as a CGI in a default Apache configuration it will run as the web server user id. And for people who suggested naming include files with the .php extension so people can't see their code... Think about it, you are now letting people execute code out of context. Bad idea. -Rasmus

« previous php.general (#103870) next »