Re: Security
| From: | Rasmus Lerdorf | Date: | Wed, 04 Oct 2000 15:53:30 +0000 |
| Subject: | Re: Security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-18604@lists.php.net to get a copy of this message | ||
Unless you have a server where many people are creating scripts and you
don't want them being able to see each others files then there is no poing
using safe-mode. Safe-mode does not help the overall security of the
server from an external point of view.
-Rasmus
> I have built a php-based website for my kids' elementary school, and now
> need to convince the IT gods at the school district that this php-thing
> isn't a security risk <grin>...
>
> Seriously, I would appreciate any comments or observations people would care
> to pass along about their experiences with the security of php. FWIW, I
> always compile it with safe mode enabled (and as a dynamically-loaded module
> under apache).
>
> In my own simple-minded tests I haven't even been able to build a script
> that deletes files in the html document tree (not even ones with owner/group
> permissions of rw and owner/group set to nobody/users; which is
> interesting).
>
> Thanx in advance for any feedback.
>
> - Mark
>
>
>