note 19188 added to ref.session
| From: | avbentem at php2 dot chek dot com | Date: | Tue, 19 Feb 2002 10:41:04 +0000 |
| Subject: | note 19188 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-26784@lists.php.net to get a copy of this message | ||
I just wrote:
:: a simple PHP script [..] would reveal the
:: code anyway
Note that if open_basedir is not strict enough, then one can even open hidden files in the
directories of other virtual hosts, like Apache's .htaccess, with a simple PHP script. So,
using
SetEnv MySecretKey xyz
in .htaccess and
getenv( 'MySecretKey' )
in a PHP script, is less secure than one may expect. Well, at least the value would not be printed
if the PHP source code is shown to a visitor due to a misconfiguration of the web server...
So, if one wants to grant the users access to /tmp then the server administrator could
- create a directory /sessions
- make it accessible to the web server only
- set session.save_path to /sessions
- set open_basedir to ".:/tmp/"
Arjan.
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+19188
http://master.php.net/manage/user-notes.php?action=delete+19188
http://master.php.net/manage/user-notes.php?action=reject+19188