Security implications - CGI vs module
| From: | Daniel Baldoni | Date: | Tue, 21 Aug 2001 09:42:22 +0000 |
| Subject: | Security implications - CGI vs module | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-63663@lists.php.net to get a copy of this message | ||
G'day folks,
It's been mentioned that the module approach to installing PHP4 has some
security implications (as compared to the separate interpreter and using
CGIs).
My question is:
For sites which do not have user-installed files (i.e. all web-
content is provided by the site-owner), what risks are there in the
module approach?
Thanks for any information.
Ciao.
--
-------------------------------------------------------+---------------------
Daniel Baldoni BAppSc, PGradDipCompSci | Technical Director
require 'std/disclaimer.pl' | LcdS Pty. Ltd.
-------------------------------------------------------+ 856B Canning Hwy
Phone/FAX: +61-8-9364-8171 | Applecross
Mobile: 041-888-9794 | WA 6153
URL: http://www.lcds.com.au/ |
Australia
-------------------------------------------------------+---------------------
"Any time there's something so ridiculous that no rational systems programmer
would even consider trying it, they send for me."; paraphrased from "King Of
The Murgos" by David Eddings. (I'm not good, just crazy)