Re: Is this secure enough?
| From: | Dean Hall | Date: | Mon, 21 Aug 2000 16:12:39 +0000 |
| Subject: | Re: Is this secure enough? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12765@lists.php.net to get a copy of this message | ||
> I'm sorry? If someone gets control of your server they can access all
> the files, regardless of permissions (since the server has to be able to
> access it, anyone controlling the server can access it). If they don't
> get control of your server they can't access the files either
> irrespective of permissions.
Huh? You're saying that you don't have to worry about other shell users
looking at your files? Yes you do! Other people with shell access to the
server can look at your files if your permissions aren't restrictive
enough. As for someone "taking over" the server, I've never heard of
this. WU_FTP had such a weakness where a buffer overflow exploit could be
used to get a shell as root, but Apache? I've never heard of anyone
getting shell access through the webserver. You really don't have anything
to worry about there.
>
> The only thing I worry about is misconfiguring the server or misnaming a
> file so it gets downloaded as text instead of parsed. This issue has
> nothing to do with permissions. So in my webroot each file is basically
> a 3-liner:
The only way that will happen is if you give your file a bad extension not
recognized by the server as belonging to any module.
>
> <?
> include(something);
> ?>
>
> This way if for whatever reason the file gets downloaded it reveals
> nothing.
If you're paranoid, you should be paranoid about things that are more
likely to happen, and people with shell access looking at your files is
possible, as opposed to your other fears.
Dean.