note 19188 deleted from ref.session by sniper

From: Date: Sun, 28 Jul 2002 01:02:58 +0000
Subject: note 19188 deleted from ref.session by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-33765@lists.php.net to get a copy of this message
I just wrote: :: a simple PHP script [..] would reveal the :: code anyway Note that if open_basedir is not strict enough, then one can even open hidden files in the directories of other virtual hosts, like Apache's .htaccess, with a simple PHP script. So, using SetEnv MySecretKey xyz in .htaccess and getenv( 'MySecretKey' ) in a PHP script, is less secure than one may expect. Well, at least the value would not be printed if the PHP source code is shown to a visitor due to a misconfiguration of the web server... So, if one wants to grant the users access to /tmp then the server administrator could - create a directory /sessions - make it accessible to the web server only - set session.save_path to /sessions - set open_basedir to ".:/tmp/" Arjan.

« previous php.notes (#33765) next »