note 30410 deleted from security.apache by bjori
| From: | bjori@php.net | Date: | Wed, 12 Apr 2006 14:41:50 +0000 |
| Subject: | note 30410 deleted from security.apache by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-107882@lists.php.net to get a copy of this message | ||
Note Submitter: MartinPierre
----
Just removing the read right for Directories will not solve all the problems :
If the user is using a well-known PHP Application which always stores it's database password in
a well known file, it is easy to deduct the name of the file !!
As for Safemode, it disables features that are required for several programs.
The only solution for the PHP module, would be to support Suexec, which could be made optional...
But at least, *nix installtion COULD be made more secure...
I know I certainly use suexec for Perl, but the only way to do so for PHP is running it as a CGI,
which is not a practical solution...