note 23048 deleted from security.apache by bjori

From: Date: Wed, 12 Apr 2006 14:39:28 +0000
Subject: note 23048 deleted from security.apache by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-107879@lists.php.net to get a copy of this message
Note Submitter: xwolf at xwolf dot de ---- In response to rick@brainscraps.com: Your comment to hallow@webmages.com shows a lack of understanding into the problem. Safe mode helps only for users with access by ftp or content-managers, which allow access in defined directories only. On bigger sites, users for virtual not only have ftp / scp, but also access to the filesystem. Due to the fact, that php-files dont get chroot'ed by suexec and mostly the users are not part of the webservers unix-group, php-files have to be global readable. THIS is a lack in security, cause now everyone with access to the filesystem may read php-files from other virtual domains. Safe mode doesnt help here. If php would support suexec, people could give read-rights to theirself only. But php don't care about suexec. Therefor php IS bad for virtual hosting WITH many different users. Please do some research before posting misleaded opinions like yours above, because they can mislead new PHP users. Running under CGI is the only solution to get a bit more security on systems with access to the filesystem for users.

« previous php.notes (#107879) next »