Re: php engine, safe mode and per directory settings
| From: | Robert Mena | Date: | Sat, 09 Dec 2000 23:53:41 +0000 |
| Subject: | Re: php engine, safe mode and per directory settings | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-29513@lists.php.net to get a copy of this message | ||
Hi, thanks for the reply. It worked great.
I am configuring the new server which will have ftp
users so they can manage their sites. Some will have
php engine turned on and others dont.
As a security measure i'd like to deny access to
system and other users files, so a malicious one wont
be able to scan and read password/db files.
Reading the options I came up with something like this
:
<Directory /var/www/html/jail/>
php_admin_value doc_root "/var/www/html/jail/"
php_admin_flag safe_mode on
php_admin_value open_basedir "/var/www/html/jail/"
</Directory>
Is this "secure" enough ?
Do you think safe_mode_exec_dir is necessary ?
Some users have scripts that handle file upload. Is
it possible to define a tmp upload dir outside the
open_basedir ? Or can I specify multiple dirs ?
The other solution would be creating a /tmp directory
in each user directory that needs upload support and
configure upload_tmp_dir, right ?
Thanks.
-
>
> php_flag engine on
>
> php_value error_reporting "E_ALL & ~E_NOTICE"
> ; not sure about this one, maybe it requires numeric
> value
>
> php_admin_flag register_globals off
> ; cannot be overwritten in a .htaccess file
>
__________________________________________________
Do You Yahoo!?
Yahoo! Shopping - Thousands of Stores. Millions of Products.
http://shopping.yahoo.com/