RE: [PHP] Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 18:01:08 +0000
Subject: RE: [PHP] Keeping "Secrets" in PHP Files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104385@lists.php.net to get a copy of this message
On 28 Jun 2002 at 15:07, Brian McGarvie wrote: > This is a problem that affects many webhosts... the issue is more of > trusting other users who have shell access to the server in > question... I have been trying to help a hosting company address this > issue, but short of dissallowing shell/ssh access their is no way to > stop another user logging into the shell and browser other peoples > files... If I am wrong then I would like to be enlightened! > > Which is is hy the company above only give out ssh accounts to users > with valid reasons for needing ssh access. Good system administration and knowledge of your operating system and the computer allows that all users can at least have a SSH account. It is extremely easy for the lazy and less knowledgeable to simply turn off what they don't understand or are too lazy to configure. I've used the hosting services of a company that was called iserver for about 7 years now. I'm not system administrator but they gave me what was essentially a "copy" of a server. I have my own apache conf files, sendmail cf, passwd file, etc. .... I play at system administrator. All of this on a virtual server with about 50 other customers. They provide telnet (not just SSH) access. I worked for a company where we had over 200 websites hosted with them. Lots of ecommerce. Never any security problems. I've had the misfortune to install applications for other people hosted on other systems. Nearly every case was a nightmare or I had to "ask" their host to do this or that for me. In 7 years at iserver I've had to ask for about 2 things (restart my postgresql database for me .... but then I think I deleted some essential files) .. yes, you get YOUR OWN mysql and postgresql database ... anyhow now I'm ranting. So anyhow, the above impacts on this: > > Thanks for the reply. But changing the ground read permission of > > the PHP files wouldn't help, either, would it? Because the other > > users who have web sites can just create a PHP file that reads my > > PHP files from one of their pages (which would be running in group > > "websecret"). If you are using a mickey mouse outfit I guess yes. What do people expect when they pay US$4.95 a month. I dunno. > Yep. If Apache and PHP can access a file, either directly through the > web, or through an include()/require(), etc, then anyone on your > machine can access that file. All PHP scripts run as the same user, > the Apache user, so the system can't tell the difference between your > script including a file, and someone else's script including a file. Again, this seem true (I am not a sysadmin although I play one from time to time) if everyone were using the same apache server. In the case of my virtual hosting the Apache server runs as ME and ditto for all other users on the system. How they get this to work and have tremendous uptime ... I dunno ... but I know what I get. I did not follow the referenced previous thread but if you have "secrets" you should put those files above your document root. If you cannot trust your hosting environment then the solution is to find one you can trust or get your own box. Peter

« previous php.general (#104385) next »