Re: Is this secure enough?

From: Date: Mon, 21 Aug 2000 08:18:24 +0000
Subject: Re: Is this secure enough?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12733@lists.php.net to get a copy of this message
Claude Cormier wrote: > > The way I see it is to have the cgi-bin directory with permissions 701. > With a copy of the PHP interpreter in this directory with permissions > 501, webusers can only execute your scripts. > > Why give the web users or shell users read acces to your stuff. Store > you PHP files in that directory with permissions 600. Have your MYSQL > data in a data directory with permission 700. The only file you live in > your web root are the index.html and other htmls. > > This set up seems to be working fine for me and one expert told me it is > an unbreakable setup. > I'm sorry? If someone gets control of your server they can access all the files, regardless of permissions (since the server has to be able to access it, anyone controlling the server can access it). If they don't get control of your server they can't access the files either irrespective of permissions. The only thing I worry about is misconfiguring the server or misnaming a file so it gets downloaded as text instead of parsed. This issue has nothing to do with permissions. So in my webroot each file is basically a 3-liner: <? include(something); ?> This way if for whatever reason the file gets downloaded it reveals nothing. Ciao, Andreas BTW, it is OK to cut the 300 or so lines you aren't responding to whey you reply ;-).

« previous php.general (#12733) next »