Re: Is this secure enough?

From: Date: Mon, 21 Aug 2000 16:12:39 +0000
Subject: Re: Is this secure enough?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12765@lists.php.net to get a copy of this message
> I'm sorry? If someone gets control of your server they can access all > the files, regardless of permissions (since the server has to be able to > access it, anyone controlling the server can access it). If they don't > get control of your server they can't access the files either > irrespective of permissions. Huh? You're saying that you don't have to worry about other shell users looking at your files? Yes you do! Other people with shell access to the server can look at your files if your permissions aren't restrictive enough. As for someone "taking over" the server, I've never heard of this. WU_FTP had such a weakness where a buffer overflow exploit could be used to get a shell as root, but Apache? I've never heard of anyone getting shell access through the webserver. You really don't have anything to worry about there. > > The only thing I worry about is misconfiguring the server or misnaming a > file so it gets downloaded as text instead of parsed. This issue has > nothing to do with permissions. So in my webroot each file is basically > a 3-liner: The only way that will happen is if you give your file a bad extension not recognized by the server as belonging to any module. > > <? > include(something); > ?> > > This way if for whatever reason the file gets downloaded it reveals > nothing. If you're paranoid, you should be paranoid about things that are more likely to happen, and people with shell access looking at your files is possible, as opposed to your other fears. Dean.

« previous php.general (#12765) next »