Re: Keeping "Secrets" in PHP Files
| From: | 1LT John W. Holmes | Date: | Fri, 28 Jun 2002 14:26:59 +0000 |
| Subject: | Re: Keeping "Secrets" in PHP Files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104334@lists.php.net to get a copy of this message | ||
>This is a problem that affects many webhosts... the issue is more of
trusting other users who have shell access >to the server in question... I
have been trying to help a hosting company address this issue, but short of
>dissallowing shell/ssh access their is no way to stop another user logging
into the shell and browser other >peoples files... If I am wrong then I
would like to be enlightened!
>Which is is hy the company above only give out ssh accounts to users with
valid reasons for needing ssh >access.
With shell access, you can't see each others files. This is where the
permissions come into play, because you are logged into the box as a
specific user, you can only access your files. If I change the permissions
on my files, you can't see them.
With PHP however, all PHP scrips run as the same user. So you don't need
shell access at all, you just write a php script that lists the contents of
a directory, any directory, any user, so long as apache/php have access to
read the file.
---John Holmes...