note 18666 added to ref.session

From: Date: Thu, 31 Jan 2002 02:21:40 +0000
Subject: note 18666 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-26056@lists.php.net to get a copy of this message
For the people fearing local exploits there are to solutions in case you are running under unix: One would be to make every user (except the www-servers user) belong to a group (say users) and make public_html owned by <user>.users and chmod 705 -> people belonging to users have zero permissions but others (including www server ) have read and execute. Another possiblity (which looks cleaner :) is to have public_html (and session directory with files handler) belong to group www (or something) that only the web server belongs to and have them chmod 750. You need to chown them with root account or sudo script or something though.. Now if you encrypt the session data, other users can't get the key from your public_html. You can also have your home directory 705 (or 701) and have web pages under it but nobody belonging to users-group could access it. You should be doing this anyway on multi-user environments if you have anything sensitive in your home directory. -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+18666 http://master.php.net/manage/user-notes.php?action=delete+18666 http://master.php.net/manage/user-notes.php?action=reject+18666

« previous php.notes (#26056) next »