RE: [PHP] Hiding the source!
| From: | Richard Fairthorne | Date: | Thu, 17 Aug 2000 20:20:23 +0000 |
| Subject: | RE: [PHP] Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12347@lists.php.net to get a copy of this message | ||
Oops! I meant to say no user can run CGI's or SSI as <webserver>.
Richard Fairthorne
Ebony Run - Vocalist - http://www.mp3.com/ebonyrun
--
Click here for the best underground rock music on the net!
http://www.rockrealm.com
-----Original Message-----
From: Richard Fairthorne [mailto:info@ebonyrun.com]
Sent: August 17, 2000 4:18 PM
To: Claude Cormier; Matt McClanahan
Cc: James Atkinson; PHP
Subject: RE: [PHP] Hiding the source!
I think I have a solution that works now:
Files and directories are owned by <subscriber>:<webserver>, php (and CGI's)
run as <subscriber>. File permissions are set as -rwxr-x--- .
Then just enforce a policy that no users can run CGI's or SSI as <nobody>.
Sound sound?
Richard Fairthorne
Ebony Run - Vocalist - http://www.mp3.com/ebonyrun
--
Click here for the best underground rock music on the net!
http://www.rockrealm.com
-----Original Message-----
From: Claude Cormier [mailto:techsupport@devises-or.com]
Sent: August 17, 2000 3:40 PM
To: Matt McClanahan
Cc: James Atkinson; PHP
Subject: Re: [PHP] Hiding the source!
Matt McClanahan wrote:
>
> On Thu, 17 Aug 2000, Claude Cormier wrote:
>
> > Isn't it a question of permission... if you don't give "r" access to
> > others and keep this permission for the owner only... How can a file be
> > read ?
>
> It's an issue of group or global access in many cases. A common
> requirement of all PHP scripts on a given instance of a web server is that
> they need to be readable, somehow, by the user that the web server
> runs as (We assume that the web server is not running as root, since
> that's a Very Bad(tm) idea).
I am confused here.
Assuming you have a web directory that goes like:
../www.mydomain.com
/cgi-bin
index.html
If the cgi-bin dir has no group permissions and only "x" for public
users, then what you said above doesn't apply. Right (or worng) ? No
matter what the PHP source are in cgi-bin, no body can read them.
> For example, suppose you have five users that write PHP code on your
> server. Each owns their own script, but the web server user needs access
> to them all, somehow.
When you say the "web server user needs acess to them all"... you mean
via the PHP interpreter?
> One common solution is to group-own all the PHP
> scripts to the group that the web server user is ('websites', for
> example). However, as a consequence of this setup, all five users
> have read access to the scripts owned by the other users.
Isn't having each user set up with its one copy of the PHP interprer
(with "x" only to gorup and public) a better solution ?
Claude
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net