note 14590 rejected and deleted from security.apache.php by andy
| From: | andy@php.net | Date: | Sun, 05 Aug 2001 19:32:04 +0000 |
| Subject: | note 14590 rejected and deleted from security.apache.php by andy | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-16341@lists.php.net to get a copy of this message | ||
Question is how do you give PHP access to virtual hosts under Apache (win2k pro)
I have a drive set for the web documents. Each virtual host has its own folder. Each user of the
virtual host has his own ftp account. But the problem is that a user can actually delete files from
other folders that are ABOVE his root folder. How can this be stopped.
Basicaly I want a method so that a user can run php only in his own home folder. If he tries to
access anything outside his home folder, he should not be allowed to do so.
Also the use may not be allowed to run system comamnds.
Basically, he should only be able to do ANYTHING in his own folder. He should not even be able to
list contents of any other folder. How can this be done.
If PHP cant support something like this, its not worth using PHP, except on a personal server.
Someone mentioned something about 'php_admin_value open_basedir /your/virtual/dir/htdocs'
to be used on a virtual host basis. But I did not quite understand how to use it or where to use
it, as no example was provided.