tip for next PHP version

From: Date: Fri, 17 Aug 2001 19:39:50 +0000
Subject: tip for next PHP version
Groups: php.mirrors 
Request: Send a blank email to php-mirrors+get-6068@lists.php.net to get a copy of this message
Hello PHP, I think PHP is a great project and I have a tip for you to improve the use of PHP in a safe way on shared servers. The problem on shared servers is that users are able to delete or view files in the directory that belongs to other users on the same server. Currently, PHP offers effective ways to prevent this, but I think the job can be done more simple: why not add the following configuration option to php.ini in future releases?? restricted_access_of_scripts = On | Off -> On: when a php-script is executed on the server it can only modify files in the directory where the script is located, or in directories lower than that in the directory tree. -> Off: when a php-script is executed it can modify any file on the entire server. -------- EXAMPLE 1 (restricted_access_of_scripts = On): myserver/users/user-a/delete.php wants to delete myserver/users/user-b/secret.doc. This is not possible becouse the file is not in the same directory as the php script. EXAMPLE 2 (restricted_access_of_scripts = Off): myserver/users/user-a/delete.php wants to delete myserver/users/user-b/secret.doc. This is possible becouse the file is located on the same server. EXAMPLE 3 (restricted_access_of_scripts = On): myserver/users/user-a/delete.php wants to delete myserver/users/user-a/images/picture.gif. This is possible becouse the file is in the same directory tree as the php script. ------- I hope this tip can be of any help for you. If not, just throw it in the wastepaperbasket or something. This mail is from a very satisfied user of PHP, I have a lot of respect for the creators of PHP andd the fact that it is free. Jeroen Wegman Netherlands. __________________________________________________ Do You Yahoo!? Make international calls for as low as $.04/minute with Yahoo! Messenger http://phonecard.yahoo.com/

« previous php.mirrors (#6068) next »