note 54858 deleted from features.safe-mode by cmb
| From: | cmb@php.net | Date: | Tue, 13 Oct 2020 20:04:37 +0000 |
| Subject: | note 54858 deleted from features.safe-mode by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-215593@lists.php.net to get a copy of this message | ||
Note Submitter: jo at durchholz dot org
----
Note that safe mode is largely useless. Most ISPs that offer Perl also offer other scripting
languages (mostly Perl), and these other languages don't have the equivalent of PHP.
In other words, if PHP's safe mode won't allow vandals into your web presence, they will
simply use Perl.
Also, safe mode prevents scripts from creating and using directories (because they will be owned by
the WWW server, not by the user who uploaded the PHP script). So it's not only useless,
it's also a hindrance.
The only realistic option is to bugger the Apache folks until they run all scripts as the user
who's responsible for a given virtualhost or directory.