Re: Is this secure enough?

From: Date: Mon, 21 Aug 2000 14:01:44 +0000
Subject: Re: Is this secure enough?
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-12761@lists.php.net to get a copy of this message
Andreas Pour wrote: > > Claude Cormier wrote: > > > > The way I see it is to have the cgi-bin directory with permissions 701. > > With a copy of the PHP interpreter in this directory with permissions > > 501, webusers can only execute your scripts. > > > > Why give the web users or shell users read acces to your stuff. Store > > you PHP files in that directory with permissions 600. Have your MYSQL > > data in a data directory with permission 700. The only file you live in > > your web root are the index.html and other htmls. > > > > This set up seems to be working fine for me and one expert told me it is > > an unbreakable setup. > > > > I'm sorry? If someone gets control of your server they can access all > the files, regardless of permissions (since the server has to be able to > access it, anyone controlling the server can access it). What do you mean by "gets control of your server" ? Ain't that true on any installation? >If they don't > get control of your server they can't access the files either > irrespective of permissions. Well if on your system, scripts run as though the owner started the program himself vs with the web server software identity, then all you need is "x" to the PHP interpreter. No matter who access the server, he execute only the interpreter which, itself will read the PHP scripts. Where is the flaw? > The only thing I worry about is misconfiguring the server or misnaming a > file so it gets downloaded as text instead of parsed. But how can a file be downed loaded if only the owner has read access to the directory where the file is ?

« previous php.general (#12761) next »