note 2481 modified in install.apache by imajes
| From: | imajes@php.net | Date: | Sat, 19 Jan 2002 06:49:53 +0000 |
| Subject: | note 2481 modified in install.apache by imajes | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-25119@lists.php.net to get a copy of this message | ||
You could configure Apache to only allow php3s from a specific directory to be served, and only
allow trusted people (e.g. you) access to it. Something like the "cautious" approach to
cgi generally recommended. (cgi has the same security feature - a shell-script cgi looking like
'cat /etc/passwd' works.)
I won't try to put together the necessary bit in httpd.conf for it, as I am neither an expert
nor a novice with oodles of spare time. You will want to deny all php3's, then allow those in
/home/httpd/php3/ to be served from the php module.
Sticking the
AddType *** .php3 within a <Directory /home/httpd/php3> block may acheive the latter. You will
also want to stop local .htaccess files overriding this, so that users can't enable the AddType
where it shouldn't be.
Apache's security page may help you here.
Of course, if your users are so untrustworthy and/or stupid, they will set up 'cp /etc/password
~/public_html/passwords.txt' to automatically execute periodically. Shadow passwords are the
go here.
--was--
You could configure Apache to only allow php3s from a specific directory to be served, and only
allow trusted people (e.g. you) access to it. Something like the "cautious" approach to
cgi generally recommended. (cgi has the same security feature - a shell-script cgi looking like
'cat /etc/passwd' works.)
<P>
I won't try to put together the necessary bit in httpd.conf for it, as I am neither an expert
nor a novice with oodles of spare time. You will want to deny all php3's, then allow those in
/home/httpd/php3/ to be served from the php module.
Sticking the
<PRE>AddType *** .php3</PRE> within a <Directory /home/httpd/php3 > block
may acheive the latter. You will also want to stop local .htaccess files overriding this, so that
users can't enable the AddType where it shouldn't be.
Apache's security page may help you here.
<P>
Of course, if your users are so untrustworthy and/or stupid, they will set up 'cp /etc/password
~/public_html/passwords.txt' to automatically execute periodically. Shadow passwords are the
go here.
http://www.php.net/manual/en/install.apache.php