note 26284 added to security.apache
| From: | live_beer at hotmail dot com | Date: | Fri, 25 Oct 2002 02:02:20 +0000 |
| Subject: | note 26284 added to security.apache | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-38524@lists.php.net to get a copy of this message | ||
I just wanted to make a comment related to securing files on a virtual host.
The system I was running scripts on was running in safe mode, and jailed the scripts to the virtual
server. As well, I had only FTP access which showed only a restricted amount of the server. The PHP
system was secure, and for 1 minute I thought so were my scripts and their contents.
The flaw was, like most servers, PHP is hardly the only thing running. Less then 2 minutes later I
was browsing other virtual hosts with a Perl script.
I know this is not a weakness with PHP, but someone with bad intentions doesnt care how they read
the database passwords from your PHP script, they just care that they can. The moral is you can lock
the front door, deadbolt and nail it shut, but its all for no good if the back door is open. When
considering security of your scripts, it is system security, not just PHP security that you need to
be concerned about.
--
http://www.php.net/manual/en/security.apache.php
http://master.php.net/manage/user-notes.php?action=edit+26284
http://master.php.net/manage/user-notes.php?action=delete+26284
http://master.php.net/manage/user-notes.php?action=reject+26284