RE: [PHP] Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 21:54:31 +0000
Subject: RE: [PHP] Keeping "Secrets" in PHP Files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104432@lists.php.net to get a copy of this message
-----Original Message----- > From: 1LT John W. Holmes [mailto:holmes072000@charter.net] > Subject: Re: [PHP] Keeping "Secrets" in PHP Files > With shell access, you can't see each others > files. This is where the permissions come into > play, because you are logged into the box as a > specific user, you can only access your files. > If I change the permissions > on my files, you can't see them. I've been thinking some more about the issue of keeping PHP source files secure in a shared hosting environment. I've now convinced myself that there is simply no way to protect these files, even if safe_mode is turned on, as long as other users can have telnet (or ssh) access to the box. Here's my thinking ... First off, I am assuming that - we are discussing a Unix-variant environment (I don't know enough about Windows to comment) - the web server does NOT run as root In this case, your PHP files must be protected so that the web server can read them. This is either because their protection allows "world" read permission, or because you allow group read permission & the web server & you are in the same group. Obviously, if your PHP files have world read permission, then any other user on the box can read them directly using their favorite text editor. So, let's assume that the web server has access to the file because of group membership. But, in this case, EVERY other user must be in the same group (so that the web server can access their files). So, once again we see that any user can directly access your PHP files. So unless I'm missing something, safe_mode provides no protection in a Unix environment where - the web server does not run as root - other users have telnet access to the box I hope wrong. Can anyone find the hole in my reasoning? -- JR

« previous php.general (#104432) next »