Re: Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 14:26:59 +0000
Subject: Re: Keeping "Secrets" in PHP Files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104334@lists.php.net to get a copy of this message
>This is a problem that affects many webhosts... the issue is more of trusting other users who have shell access >to the server in question... I have been trying to help a hosting company address this issue, but short of >dissallowing shell/ssh access their is no way to stop another user logging into the shell and browser other >peoples files... If I am wrong then I would like to be enlightened! >Which is is hy the company above only give out ssh accounts to users with valid reasons for needing ssh >access. With shell access, you can't see each others files. This is where the permissions come into play, because you are logged into the box as a specific user, you can only access your files. If I change the permissions on my files, you can't see them. With PHP however, all PHP scrips run as the same user. So you don't need shell access at all, you just write a php script that lists the contents of a directory, any directory, any user, so long as apache/php have access to read the file. ---John Holmes...

« previous php.general (#104334) next »