RE: [PHP] Keeping "Secrets" in PHP Files
| From: | Peter J. Schoenster | Date: | Fri, 28 Jun 2002 18:01:08 +0000 |
| Subject: | RE: [PHP] Keeping "Secrets" in PHP Files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104385@lists.php.net to get a copy of this message | ||
On 28 Jun 2002 at 15:07, Brian McGarvie wrote:
> This is a problem that affects many webhosts... the issue is more of
> trusting other users who have shell access to the server in
> question... I have been trying to help a hosting company address this
> issue, but short of dissallowing shell/ssh access their is no way to
> stop another user logging into the shell and browser other peoples
> files... If I am wrong then I would like to be enlightened!
>
> Which is is hy the company above only give out ssh accounts to users
> with valid reasons for needing ssh access.
Good system administration and knowledge of your operating system and the computer allows that all
users can at least have a SSH account. It is extremely easy for the lazy and less knowledgeable to
simply turn off what they don't understand or are too lazy to configure. I've used the
hosting services of a company that was called iserver for about 7 years now. I'm not system
administrator but they
gave me what was essentially a "copy" of a server. I have my own apache conf files,
sendmail cf, passwd file, etc. .... I play at system administrator. All of this on a virtual server
with about 50 other
customers. They provide telnet (not just SSH) access. I worked for a company where we had over 200
websites hosted with them. Lots of ecommerce. Never any security problems. I've had the
misfortune to install applications for other people hosted on other systems. Nearly every case was
a nightmare or I had to "ask" their host to do this or that for me. In 7 years at iserver
I've had to ask for
about 2 things (restart my postgresql database for me .... but then I think I deleted some essential
files) .. yes, you get YOUR OWN mysql and postgresql database ... anyhow now I'm ranting.
So anyhow, the above impacts on this:
> > Thanks for the reply. But changing the ground read permission of
> > the PHP files wouldn't help, either, would it? Because the other
> > users who have web sites can just create a PHP file that reads my
> > PHP files from one of their pages (which would be running in group
> > "websecret").
If you are using a mickey mouse outfit I guess yes. What do people expect when they pay US$4.95 a
month. I dunno.
> Yep. If Apache and PHP can access a file, either directly through the
> web, or through an include()/require(), etc, then anyone on your
> machine can access that file. All PHP scripts run as the same user,
> the Apache user, so the system can't tell the difference between your
> script including a file, and someone else's script including a file.
Again, this seem true (I am not a sysadmin although I play one from time to time) if everyone were
using the same apache server. In the case of my virtual hosting the Apache server runs as ME and
ditto
for all other users on the system. How they get this to work and have tremendous uptime ... I dunno
... but I know what I get.
I did not follow the referenced previous thread but if you have "secrets" you should put
those files above your document root. If you cannot trust your hosting environment then the solution
is to find one
you can trust or get your own box.
Peter