note 19186 deleted from ref.session by sniper
| From: | sniper@php.net | Date: | Sun, 28 Jul 2002 01:03:21 +0000 |
| Subject: | note 19186 deleted from ref.session by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-33767@lists.php.net to get a copy of this message | ||
One addition to mystran's note:
:: make every user (except the www-servers
:: user) belong to a group (say users) and
:: make public_html owned by <user>.users
:: and chmod 705
True, to limit access from the Unix shell. However, if in php.ini open_basedir is left to its
default, then a simple PHP script (running with the server's permissions) would reveal the code
anyway. In fact, such a script also reveals the session IDs in /tmp, as explained in the warning of
session.save_path above.
Arjan.