Re: MySQL Admin Tool

From: Date: Thu, 14 Feb 2002 10:22:50 +0000
Subject: Re: MySQL Admin Tool
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-84718@lists.php.net to get a copy of this message
Liam MacKenzie wrote:
And also... How do I go about securing PHP functions. For example, at the moment Joe can upload a PHP script that deletes /etc/named.conf. NOT GOOD! Surely this is a general security issue? If an ordinary user is allowed to delete /etc/named.conf (whether by PHP, Perl or a command line "rm /etc/named.conf") then the permissions are not right (only root normally having write permission). Joe may be able to run a script that _tries_ to delete /etc/named.conf but the permissions should not allow it.
Or am I missing something? Regards Chris

« previous php.general (#84718) next »