note 30410 deleted from security.apache by bjori

From: Date: Wed, 12 Apr 2006 14:41:50 +0000
Subject: note 30410 deleted from security.apache by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-107882@lists.php.net to get a copy of this message
Note Submitter: MartinPierre ---- Just removing the read right for Directories will not solve all the problems : If the user is using a well-known PHP Application which always stores it's database password in a well known file, it is easy to deduct the name of the file !! As for Safemode, it disables features that are required for several programs. The only solution for the PHP module, would be to support Suexec, which could be made optional... But at least, *nix installtion COULD be made more secure... I know I certainly use suexec for Perl, but the only way to do so for PHP is running it as a CGI, which is not a practical solution...

« previous php.notes (#107882) next »