Re: PHP as an APACHE MODULE
| From: | Linux | Date: | Tue, 12 Dec 2000 08:46:02 +0000 |
| Subject: | Re: PHP as an APACHE MODULE | ||
| References: | 1 | Groups: | php.general php.general |
| Request: | Send a blank email to php-general+get-29843@lists.php.net to get a copy of this message | ||
Yes sorry.
I have a linux server with apache1.3.12 and php4 loaded as a DSO module.
As my users can create (via ftp) home page with php, they can introduce bad
script and damage my server.
Also, if some password were stolen, an hacker can write and upload a script to
stole information and damage my server.
My questions now are:
How can i secure my server against php attack??? (I cannot use PHP CGI for
various reasons).
There was a method to limit php only in some directory without using CGI????
Any hint will be accepted.
Thanks.
On Tue, 12 Dec 2000, Richard Lynch wrote:
> > I need a solution in securing my php loaded as an apache module.
> > For many reasons i cannot run PHP CGI, but i would like to implement
> security
> > too.
>
> Securing it how? Against what? In what circumstances?
>
> Security is not an on/off switch -- This problem is unanswerable without
> considerably more detail about your concerns/needs.
>
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net