note 18666 added to ref.session
| From: | mystran at wasteland dot pp dot htv dot fi | Date: | Thu, 31 Jan 2002 02:21:40 +0000 |
| Subject: | note 18666 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-26056@lists.php.net to get a copy of this message | ||
For the people fearing local exploits there are to solutions in case you are running under unix:
One would be to make every user (except the www-servers user) belong to a group (say users) and make
public_html owned by <user>.users and chmod 705 -> people belonging to users have zero
permissions but others (including www server ) have read and execute.
Another possiblity (which looks cleaner :) is to have public_html (and session directory with files
handler) belong to group www (or something) that only the web server belongs to and have them chmod
750. You need to chown them with root account or sudo script or something though..
Now if you encrypt the session data, other users can't get the key from your public_html. You
can also have your home directory 705 (or 701) and have web pages under it but nobody belonging to
users-group could access it. You should be doing this anyway on multi-user environments if you have
anything sensitive in your home directory.
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+18666
http://master.php.net/manage/user-notes.php?action=delete+18666
http://master.php.net/manage/user-notes.php?action=reject+18666