Re: Server Help
| From: | Richard Lynch | Date: | Sat, 25 Aug 2001 03:12:45 +0000 |
| Subject: | Re: Server Help | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-64390@lists.php.net to get a copy of this message | ||
> I recently realized users are able to access my base document root using
> opendir() and readdir()... I find this to be a big security risk.. I am
> wondering if anyone knows of any ways to limit it so that the user can
only
> usephp on his level,and not be able to access any server files. I hope
that
> makes sense, heh.. If you need more info,say say..
You pretty much just described open_basedir:
http://php.net/manual/en/features.safe-mode.php#features.safe-mode
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm