RE: Keeping "Secrets" in PHP Files
| From: | Philip Hallstrom | Date: | Fri, 28 Jun 2002 23:21:11 +0000 |
| Subject: | RE: Keeping "Secrets" in PHP Files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104439@lists.php.net to get a copy of this message | ||
I don't know the specifics, but I would guess there would be too much
overhead in constantly changing the group the process ran as. It's not as
big a deal with FTP because (presumably) the duration of the connection is
"long" where as for web servers it's "short". I'd be happy to be
corrected
though.
I think the real answer is if you are that concerned about the security of
your files you need to get your own dedicated server or find an ISP that
uses jails or virtual private servers.
On Fri, 28 Jun 2002, Lazor, Ed wrote:
> The hosting provider could probably implement a solution... Alter the FTP
> configuration to automatically set the group permission to that of the web
> server when you transfer files. You wouldn't need to be in the group.
> You're the owner and can modify your own files. World Read access would be
> unnecessary.
>
> Thoughts?
>
>
> -----Original Message-----
> > With shell access, you can't see each others
> > files. This is where the permissions come into
> > play, because you are logged into the box as a
> > specific user, you can only access your files.
> > If I change the permissions
> > on my files, you can't see them.
>
> In this case, your PHP files must be protected so that the web
> server can read them. This is either because their protection
> allows "world" read permission, or because you allow group read
> permission & the web server & you are in the same group.
>
> Obviously, if your PHP files have world read permission, then any
> other user on the box can read them directly using their favorite
> text editor.
>
> So, let's assume that the web server has access to the file
> because of group membership. But, in this case, EVERY other user
> must be in the same group (so that the web server can access
> their files).
>
> ****************************************************************************
> This message is intended for the sole use of the individual and entity to
> whom it is addressed, and may contain information that is privileged,
> confidential and exempt from disclosure under applicable law. If you are
> not the intended addressee, nor authorized to receive for the intended
> addressee, you are hereby notified that you may not use, copy, disclose or
> distribute to anyone the message or any information contained in the
> message. If you have received this message in error, please immediately
> advise the sender by reply email and delete the message. Thank you very
> much.
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>