Re: Security problem?
| From: | Rasmus Lerdorf | Date: | Wed, 26 Jun 2002 01:16:18 +0000 |
| Subject: | Re: Security problem? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-103870@lists.php.net to get a copy of this message | ||
> On Tue, Jun 25, 2002 at 08:53:40PM -0400, John Holmes wrote:
> >
> > I don't think this applies with PHP as a CGI on a virtual server, does
> > it? It doesn't matter if your scripts control access, if you include()
> > it or whatever, that means PHP has access to it. So does another users
> > PHP script have access to it, too?
>
> Huh? Not that I know of. PHP as CGI is running as my user id. For other
> people on the server, PHP runs as their user id. Thus, only my scripts
> have access to my files if I give them 600 permissions.
That is only the case if your server is set up to use SuExec or something
similar. By default if you simply run PHP as a CGI in a default Apache
configuration it will run as the web server user id.
And for people who suggested naming include files with the .php extension
so people can't see their code... Think about it, you are now letting
people execute code out of context. Bad idea.
-Rasmus