note 24152 added to security.apache
| From: | daniel dot eckl at gmx dot de | Date: | Thu, 08 Aug 2002 08:16:41 +0000 |
| Subject: | note 24152 added to security.apache | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-34510@lists.php.net to get a copy of this message | ||
There is a better solution than starting every virtual host in a seperate instance, which is wasting
ressources.
You can set open_basedir dynamically for every virtual host you have, so every PHP script on a
virtual host is jailed to its document root.
Example:
<VirtualHost www.example.com>
ServerName www.example.com
DocumentRoot /www-home/example.com
[...]
<Location />
php_admin_value open_basedir \ "/www-home/example.com/:/usr/lib/php/"
</Location>
</VirtualHost>
If you set safe_mode on, then the script can only use binaries in given directories (make a special
dir only with the binaries your customers may use).
Now no user of a virtual host can read/write/modify the data of another user on your machine.
Windseeker
--
http://www.php.net/manual/en/security.apache.php
http://master.php.net/manage/user-notes.php?action=edit+24152
http://master.php.net/manage/user-notes.php?action=delete+24152
http://master.php.net/manage/user-notes.php?action=reject+24152