note 13950 deleted from security.apache by bjori
| From: | bjori@php.net | Date: | Wed, 12 Apr 2006 14:38:04 +0000 |
| Subject: | note 13950 deleted from security.apache by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-107877@lists.php.net to get a copy of this message | ||
Note Submitter: hallow at webmages dot com
----
mod_php is bad for virtual hosting. If you've got 5 different vhosts running on apache, and
mod_php installed, and each of the users have some page that requires php to write something to the
disk, and they give proper permissions for the web server to do so, anyone with access to php/the
web server can do so.
Also, if their application has a config file which is blocked say by .htaccess, that contains things
like database logins and passwords, etc., it must be readable by the web server, and as such anyone
with access to write a php script can grab a copy of the file off the disk and display it.
The only way to get around this is to run a seperate instance of apache for each virtual server, or
to use the php-cgi binary and something like apache's suEXEC.