Re: setuid wrapper, exposing passwords
| From: | Teodor Cimpoesu | Date: | Fri, 29 Sep 2000 13:45:58 +0000 |
| Subject: | Re: setuid wrapper, exposing passwords | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-18043@lists.php.net to get a copy of this message | ||
Hi Mukul!
On Fri, 29 Sep 2000, Mukul Sabharwal wrote:
> Hi,
>
> does anyone know why setuid wrapper not being present releases security holes in PHP scripts. I
> had read this somewhere :
>
> \"Accessing databases through PHP is currently not recommended, as it would imply exposing
> your password to the world due to the lack of setuid wrapper (until PHP can be mode 700 of
> course).\"
>
> and can someone also explain what it really is ?
>
Should you explain in a bit more detail what's exactly your security concern
we can try.
-- teodor