Re: Security Related Problem.
| From: | nathan at 0x00 dot org | Date: | Mon, 11 Dec 2000 13:39:47 +0000 |
| Subject: | Re: Security Related Problem. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29684@lists.php.net to get a copy of this message | ||
I suggest using the CGI version of PHP with apaches suexec. I just did
this on one of our servers, I sleep much better at night.
-n
On Mon, 11 Dec 2000, Linux wrote:
> Hi all.
>
> I'm using PHP4.0.3pl1 with Linux and Apache.
> I'm using php loaded as DSO in apache, and all my .php file are interpreted as
> php source code. All was ok.
> Now my problem.
> Using php in this manner, my users can create php files for their homepage, but
> i think there was a security problem in this.
> If someone steal an ftp password and put a .php file in a directory, he can
> theorically grab file and information about my server.
> He gain nobody (or some other user) access because apache run with nobody
> permission, and he can copy, remove, etc files from a directory to another
> (stealing source code downloading with ftp).
> If i block read permission to nobody in some directory, apache cannot read the
> files in it, and this is not good for my real users.
>
> Someone can give me hint??
>
> Bye.
>
>