Re: Security Related Problem.

From: Date: Mon, 11 Dec 2000 13:39:47 +0000
Subject: Re: Security Related Problem.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29684@lists.php.net to get a copy of this message
I suggest using the CGI version of PHP with apaches suexec. I just did this on one of our servers, I sleep much better at night. -n On Mon, 11 Dec 2000, Linux wrote: > Hi all. > > I'm using PHP4.0.3pl1 with Linux and Apache. > I'm using php loaded as DSO in apache, and all my .php file are interpreted as > php source code. All was ok. > Now my problem. > Using php in this manner, my users can create php files for their homepage, but > i think there was a security problem in this. > If someone steal an ftp password and put a .php file in a directory, he can > theorically grab file and information about my server. > He gain nobody (or some other user) access because apache run with nobody > permission, and he can copy, remove, etc files from a directory to another > (stealing source code downloading with ftp). > If i block read permission to nobody in some directory, apache cannot read the > files in it, and this is not good for my real users. > > Someone can give me hint?? > > Bye. > >

« previous php.general (#29684) next »