Re: Is this secure enough?

From: Date: Mon, 21 Aug 2000 05:29:29 +0000
Subject: Re: Is this secure enough?
Groups: php.general 
Request: Send a blank email to php-general+get-12713@lists.php.net to get a copy of this message
The way I see it is to have the cgi-bin directory with permissions 701. With a copy of the PHP interpreter in this directory with permissions 501, webusers can only execute your scripts. Why give the web users or shell users read acces to your stuff. Store you PHP files in that directory with permissions 600. Have your MYSQL data in a data directory with permission 700. The only file you live in your web root are the index.html and other htmls. This set up seems to be working fine for me and one expert told me it is an unbreakable setup. Dave Jones wrote: > > But if shell users can read the web pages then they can see the exact > name of the include file. > > To include an include file that is below the web directory would you > use an extra "../" or give it an exact path starting with a "/"? When > you define a path in a php include statement, does a leading "/" define > the root of the machine or the root of the web site? > > Dean Hall wrote: > > > > Dave. > > > > The best thing to do to keep data safe is to figure out who you're keeping > > it safe from and at the same time, realize the tradeoffs in keeping it > > secure. > > > > So, do you want to keep the MySQL data secure from > > > > . Shell users on your server (people with shell access to the same machine > > you're on) or > > . Web users > > > > First, if it's shell users you're worried about, make sure the permissions > > on the directory where you keep the data prohibits them from seeing anything > > inside that directory. I'll assume you're using Unix of some degree, but the > > principle is the same for NT. I'll also assume that you need pretty liberal > > permissions so the webserver (including PHP) can read your files. The best > > way to do this then is to 'chmod 744' the directory the secure files are in. > > This means that no one can get a directory listing in those directories > > except the owner of the directory, but they can access a file if they know > > its exact name. Since PHP knows the exact name of the file, it can read it. > > Other shell users on the machine probably don't know the name of the file. > > > > If its web users you're worried about, you need to make an include directory > > BENEATH (or parallel to) the web root for your server. For instance, on the > > computers at my university, my web root is '/home/hall/public_html'. Well, I > > would make a directory called '/home/hall/include' for all my PHP includes > > (the .inc files, not the .php files). That way web users can't even see > > them -- and couldn't access them if they wanted to. Keeping them in the > > cgi-bin keeps them available to attack. If someone wants them, they can get > > them from the web -- whether you have password-protection or not. > > > > Dean Hall. > > > > ----- Original Message ----- > > From: "Dave Jones" <dave@anti.spam> > > To: <php-general@lists.php.net> > > Sent: Sunday, August 20, 2000 4.14 pm > > Subject: [PHP] Is this secure enough? > > > > > I jsut finished my first real php site and want to make sure there's > > > nothing I left out as far as unauthorized people getting to my php code > > > and MySQL data. > > > > > > I'm on a shared server (virtual domains on a web host). As far as I > > > know the domains are kept from looking at each other with .htaccess > > > (which I know isn't perfect, but should stop casual snoops). > > > > > > I have the php code that connects to the database (and contains my > > > MySQL username, password, and database name) inside an include file > > > which is stored in a subdirectory of my cgi-bin directory, and that > > > subdirectory is password protected (again, .htaccess). The rest of the > > > php is just in the pages spread throughout the web accessable folders. > > > > > > The only other thing I could come up with is to put all of the page > > > content (for all pages) inside include files that are in a password > > > protected folder and the public files contain nothing but one include > > > statement each, but this seems to be getting too paranoid. > > > > > > Since this is a shared server, I don't have access to configuring php > > > or MySQL (and the host is too large and accounts too cheap to ask for > > > anything special in that vein). Is this about as good as I can do for > > > security? > > > > > > ...Dave > > > > > > > > > -------------------- > > > To send e-mail to me replace the > > > domain name with djdesign.com > > > The phony "anti.spam" domain > > > is used to fool newsgroup e-mail > > > address harvestor 'bots. > > > ---------------------- > > > > > > -- > > > PHP General Mailing List (http://www.php.net/) > > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > > For additional commands, e-mail: php-general-help@lists.php.net > > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > For additional commands, e-mail: php-general-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > -- > > -------------------- > To send e-mail to me replace the > domain name with djdesign.com > The phony "anti.spam" domain > is used to fool newsgroup e-mail > address harvestor 'bots. > ---------------------- > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#12713) next »