Re: security
| From: | Rasmus Lerdorf | Date: | Mon, 08 Jan 2001 08:42:59 +0000 |
| Subject: | Re: security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-33202@lists.php.net to get a copy of this message | ||
Two ways:
1. most secure: run separate Apache instances as different user ids for
each user
2. will stump the average script kiddie: turn on safe_mode
-Rasmus
On Mon, 8 Jan 2001, andreas (@work) wrote:
> hi all,
>
> how do you prevent users on the same server ( virtual server )
> from accessing your scripts ?
>
>
> you know with code like this:
>
> ( first reading the directory content - then open the file they like to see copy ... )
>
>
>
> =============================
> <?
>
>
>
> function vc_of_directory($directory,$dateitypen) {
>
> $fd = opendir($directory);
>
> while($file = readdir($fd)) {
>
> if($file != "." && $file != "..") {
>
> for($i = 0;$i < count($dateitypen);$i++) {
>
> if($dateitypen == "all") {
>
> $files[] = $file;
>
> }
>
> if(eregi("\.$dateitypen[$i]$",$file)) {
>
> $files[] = $file;
>
> }
>
> }
>
> }
>
>
>
> }
>
> return $files;
>
> }
>
>
>
> ==========================================
>
>
> any ideas welcome
>
>
> andreas
> viva technologies
>
>
>
>
>
>
>
>
>
>
>
> $files =
> vc_of_directory("/usr/local/etc/httpd/htdocs/artFuntasy/flash/","all");
>
>
>
> while(list($name,$value) = each($files)) {
>
> echo $name.": ".$value."<br>";
>
> }
>
>
>
>
>
>
> $filename = "/usr/local/etc/httpd/htdocs/directory/php/myFile.php3";
> $fp = fopen($filename,"r");
>
> $content = fread($fp,filesize($filename));
> fclose($fp);
> $content = str_replace("<?","XX",$content);
> $content = str_replace("?>","XX",$content);
> echo $content;
> ?>
>
>
>
>