note 19186 deleted from ref.session by sniper

From: Date: Sun, 28 Jul 2002 01:03:21 +0000
Subject: note 19186 deleted from ref.session by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-33767@lists.php.net to get a copy of this message
One addition to mystran's note: :: make every user (except the www-servers :: user) belong to a group (say users) and :: make public_html owned by <user>.users :: and chmod 705 True, to limit access from the Unix shell. However, if in php.ini open_basedir is left to its default, then a simple PHP script (running with the server's permissions) would reveal the code anyway. In fact, such a script also reveals the session IDs in /tmp, as explained in the warning of session.save_path above. Arjan.

« previous php.notes (#33767) next »