security concerns using PHP in shared, name based virtual server setup

From: Date: Sun, 19 Aug 2001 00:27:12 +0000
Subject: security concerns using PHP in shared, name based virtual server setup
Groups: php.general 
Request: Send a blank email to php-general+get-63301@lists.php.net to get a copy of this message
currently only offer full php, postgres, mysql, et al access with virtual server accounts (chrootd hacks, or jailed environments) these are cumbersome though. Anyone have input regarding the potential security concerns with allowing users (right now only chrooted ftp users with no permissions) to run PHP files from a shared apache server. Hardening that should take place... obviously want to give users as much freedone to implement customized PHP code as possible wihout comprimising security of other users on these servers. Looking for comments and pointers to faq's/toaster instructions, etc... Dave

« previous php.general (#63301) next »