note 26284 added to security.apache

From: Date: Fri, 25 Oct 2002 02:02:20 +0000
Subject: note 26284 added to security.apache
Groups: php.notes 
Request: Send a blank email to php-notes+get-38524@lists.php.net to get a copy of this message
I just wanted to make a comment related to securing files on a virtual host. The system I was running scripts on was running in safe mode, and jailed the scripts to the virtual server. As well, I had only FTP access which showed only a restricted amount of the server. The PHP system was secure, and for 1 minute I thought so were my scripts and their contents. The flaw was, like most servers, PHP is hardly the only thing running. Less then 2 minutes later I was browsing other virtual hosts with a Perl script. I know this is not a weakness with PHP, but someone with bad intentions doesn’t care how they read the database passwords from your PHP script, they just care that they can. The moral is you can lock the front door, deadbolt and nail it shut, but its all for no good if the back door is open. When considering security of your scripts, it is system security, not just PHP security that you need to be concerned about. -- http://www.php.net/manual/en/security.apache.php http://master.php.net/manage/user-notes.php?action=edit+26284 http://master.php.net/manage/user-notes.php?action=delete+26284 http://master.php.net/manage/user-notes.php?action=reject+26284

« previous php.notes (#38524) next »