RE: [PHP] Keeping "Secrets" in PHP Files
| From: | Jonathan Rosenberg | Date: | Fri, 28 Jun 2002 21:54:31 +0000 |
| Subject: | RE: [PHP] Keeping "Secrets" in PHP Files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104432@lists.php.net to get a copy of this message | ||
-----Original Message-----
> From: 1LT John W. Holmes [mailto:holmes072000@charter.net]
> Subject: Re: [PHP] Keeping "Secrets" in PHP Files
> With shell access, you can't see each others
> files. This is where the permissions come into
> play, because you are logged into the box as a
> specific user, you can only access your files.
> If I change the permissions
> on my files, you can't see them.
I've been thinking some more about the issue of keeping PHP
source files secure in a shared hosting environment. I've now
convinced myself that there is simply no way to protect these
files, even if safe_mode is turned on, as long as other users can
have telnet (or ssh) access to the box.
Here's my thinking ...
First off, I am assuming that
- we are discussing a Unix-variant
environment (I don't know enough about
Windows to comment)
- the web server does NOT run as root
In this case, your PHP files must be protected so that the web
server can read them. This is either because their protection
allows "world" read permission, or because you allow group read
permission & the web server & you are in the same group.
Obviously, if your PHP files have world read permission, then any
other user on the box can read them directly using their favorite
text editor.
So, let's assume that the web server has access to the file
because of group membership. But, in this case, EVERY other user
must be in the same group (so that the web server can access
their files).
So, once again we see that any user can directly access your PHP
files.
So unless I'm missing something, safe_mode provides no protection
in a Unix environment where
- the web server does not run as root
- other users have telnet access to the box
I hope wrong. Can anyone find the hole in my reasoning?
--
JR