Re: Is this secure enough?
| From: | Andreas Pour | Date: | Mon, 21 Aug 2000 08:18:24 +0000 |
| Subject: | Re: Is this secure enough? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12733@lists.php.net to get a copy of this message | ||
Claude Cormier wrote:
>
> The way I see it is to have the cgi-bin directory with permissions 701.
> With a copy of the PHP interpreter in this directory with permissions
> 501, webusers can only execute your scripts.
>
> Why give the web users or shell users read acces to your stuff. Store
> you PHP files in that directory with permissions 600. Have your MYSQL
> data in a data directory with permission 700. The only file you live in
> your web root are the index.html and other htmls.
>
> This set up seems to be working fine for me and one expert told me it is
> an unbreakable setup.
>
I'm sorry? If someone gets control of your server they can access all
the files, regardless of permissions (since the server has to be able to
access it, anyone controlling the server can access it). If they don't
get control of your server they can't access the files either
irrespective of permissions.
The only thing I worry about is misconfiguring the server or misnaming a
file so it gets downloaded as text instead of parsed. This issue has
nothing to do with permissions. So in my webroot each file is basically
a 3-liner:
<?
include(something);
?>
This way if for whatever reason the file gets downloaded it reveals
nothing.
Ciao,
Andreas
BTW, it is OK to cut the 300 or so lines you aren't responding to whey
you reply ;-).