note 13950 deleted from security.apache by bjori

From: Date: Wed, 12 Apr 2006 14:38:04 +0000
Subject: note 13950 deleted from security.apache by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-107877@lists.php.net to get a copy of this message
Note Submitter: hallow at webmages dot com ---- mod_php is bad for virtual hosting. If you've got 5 different vhosts running on apache, and mod_php installed, and each of the users have some page that requires php to write something to the disk, and they give proper permissions for the web server to do so, anyone with access to php/the web server can do so. Also, if their application has a config file which is blocked say by .htaccess, that contains things like database logins and passwords, etc., it must be readable by the web server, and as such anyone with access to write a php script can grab a copy of the file off the disk and display it. The only way to get around this is to run a seperate instance of apache for each virtual server, or to use the php-cgi binary and something like apache's suEXEC.

« previous php.notes (#107877) next »