note 19188 deleted from ref.session by sniper
| From: | sniper@php.net | Date: | Sun, 28 Jul 2002 01:02:58 +0000 |
| Subject: | note 19188 deleted from ref.session by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-33765@lists.php.net to get a copy of this message | ||
I just wrote:
:: a simple PHP script [..] would reveal the
:: code anyway
Note that if open_basedir is not strict enough, then one can even open hidden files in the
directories of other virtual hosts, like Apache's .htaccess, with a simple PHP script. So,
using
SetEnv MySecretKey xyz
in .htaccess and
getenv( 'MySecretKey' )
in a PHP script, is less secure than one may expect. Well, at least the value would not be printed
if the PHP source code is shown to a visitor due to a misconfiguration of the web server...
So, if one wants to grant the users access to /tmp then the server administrator could
- create a directory /sessions
- make it accessible to the web server only
- set session.save_path to /sessions
- set open_basedir to ".:/tmp/"
Arjan.