Re: safe_mode On -- What exactly does it **DO**?
| From: | (Richard Lynch) | Date: | Sat, 10 Jun 2000 00:01:10 +0000 |
| Subject: | Re: safe_mode On -- What exactly does it **DO**? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1507@lists.php.net to get a copy of this message | ||
In article <20000602162624.A5714@esoft.com>, jbedford@esoft.com (JR
Bedford) wrote:
> First:
> ------
> Is safe_mode On only relevent in conjunction with safe_mode_exec_dir?
No, vice versa.
> In
> other words, does safe_mode On merely restrict the use of system() calls?
> Or does safe_mode On do other things, along the lines of suExec -- such as
> making sure the .php file is owned by the user that owns the directory it
> lives in, that it has certain file permissions, etc. etc. etc. Where can
> I find documentation on this?
It's more like suExec.
There's a "security" page in the online manual that may be of use...
> Second:
> -------
> What are the rules for safe_mode_exec_dir? Can I create a directory
> called allowed-progs/ and then fill it with symLinks to various programs
> throughout the file system that I will allow my users to call? Or will it
> consider a symLink a security violation and not follow it? Can I list more
> than one directory? Can I use wildcards such as /home/*/public_html/cgi ?
I think you only get one dir, and symLinks are not followed... Don't
quote me on it.
> Third: (This is a subset of question #2)
> -----
> I have set: open_basedir /home/*/public_html
I think not...
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)