note 19188 added to ref.session

From: Date: Tue, 19 Feb 2002 10:41:04 +0000
Subject: note 19188 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-26784@lists.php.net to get a copy of this message
I just wrote: :: a simple PHP script [..] would reveal the :: code anyway Note that if open_basedir is not strict enough, then one can even open hidden files in the directories of other virtual hosts, like Apache's .htaccess, with a simple PHP script. So, using SetEnv MySecretKey xyz in .htaccess and getenv( 'MySecretKey' ) in a PHP script, is less secure than one may expect. Well, at least the value would not be printed if the PHP source code is shown to a visitor due to a misconfiguration of the web server... So, if one wants to grant the users access to /tmp then the server administrator could - create a directory /sessions - make it accessible to the web server only - set session.save_path to /sessions - set open_basedir to ".:/tmp/" Arjan. -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+19188 http://master.php.net/manage/user-notes.php?action=delete+19188 http://master.php.net/manage/user-notes.php?action=reject+19188

« previous php.notes (#26784) next »