note 14590 rejected and deleted from security.apache.php by andy

From: Date: Sun, 05 Aug 2001 19:32:04 +0000
Subject: note 14590 rejected and deleted from security.apache.php by andy
Groups: php.notes 
Request: Send a blank email to php-notes+get-16341@lists.php.net to get a copy of this message
Question is how do you give PHP access to virtual hosts under Apache (win2k pro) I have a drive set for the web documents. Each virtual host has its own folder. Each user of the virtual host has his own ftp account. But the problem is that a user can actually delete files from other folders that are ABOVE his root folder. How can this be stopped. Basicaly I want a method so that a user can run php only in his own home folder. If he tries to access anything outside his home folder, he should not be allowed to do so. Also the use may not be allowed to run system comamnds. Basically, he should only be able to do ANYTHING in his own folder. He should not even be able to list contents of any other folder. How can this be done. If PHP cant support something like this, its not worth using PHP, except on a personal server. Someone mentioned something about 'php_admin_value open_basedir /your/virtual/dir/htdocs' to be used on a virtual host basis. But I did not quite understand how to use it or where to use it, as no example was provided.

« previous php.notes (#16341) next »