Security Related Problem.
| From: | Linux | Date: | Mon, 11 Dec 2000 13:15:12 +0000 |
| Subject: | Security Related Problem. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-29683@lists.php.net to get a copy of this message | ||
Hi all.
I'm using PHP4.0.3pl1 with Linux and Apache.
I'm using php loaded as DSO in apache, and all my .php file are interpreted as
php source code. All was ok.
Now my problem.
Using php in this manner, my users can create php files for their homepage, but
i think there was a security problem in this.
If someone steal an ftp password and put a .php file in a directory, he can
theorically grab file and information about my server.
He gain nobody (or some other user) access because apache run with nobody
permission, and he can copy, remove, etc files from a directory to another
(stealing source code downloading with ftp).
If i block read permission to nobody in some directory, apache cannot read the
files in it, and this is not good for my real users.
Someone can give me hint??
Bye.