note 23048 added to security.apache

From: Date: Mon, 08 Jul 2002 07:32:25 +0000
Subject: note 23048 added to security.apache
Groups: php.notes 
Request: Send a blank email to php-notes+get-32725@lists.php.net to get a copy of this message
In response to rick@brainscraps.com: Your comment to hallow@webmages.com shows a lack of understanding into the problem. Safe mode helps only for users with access by ftp or content-managers, which allow access in defined directories only. On bigger sites, users for virtual not only have ftp / scp, but also access to the filesystem. Due to the fact, that php-files dont get chroot'ed by suexec and mostly the users are not part of the webservers unix-group, php-files have to be global readable. THIS is a lack in security, cause now everyone with access to the filesystem may read php-files from other virtual domains. Safe mode doesnt help here. If php would support suexec, people could give read-rights to theirself only. But php don't care about suexec. Therefor php IS bad for virtual hosting WITH many different users. Please do some research before posting misleaded opinions like yours above, because they can mislead new PHP users. Running under CGI is the only solution to get a bit more security on systems with access to the filesystem for users. -- http://www.php.net/manual/en/security.apache.php http://master.php.net/manage/user-notes.php?action=edit+23048 http://master.php.net/manage/user-notes.php?action=delete+23048 http://master.php.net/manage/user-notes.php?action=reject+23048

« previous php.notes (#32725) next »