php apache module and file writing vs security ?
| From: | Michael Blower | Date: | Wed, 28 Nov 2001 00:34:07 +0000 |
| Subject: | php apache module and file writing vs security ? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-75824@lists.php.net to get a copy of this message | ||
I need to be able to have high security for the default web user such
that php can not write files. The level of security is such that I
can't open up directories in the web root for writing by the default www
user (php runs as this user).
Question #1: Is there a way to securly write files to the webroot in the
apache module version of PHP?
Question #2: Is it safe to install a second "CGI" copy of php on the server
with the current apache module version of php ? Would it be able to
share the same php.ini.
I'm installing on RedHat Linux, current apache module is php4.4 version.
Michael