note 30410 added to security.apache

From: Date: Mon, 17 Mar 2003 15:45:30 +0000
Subject: note 30410 added to security.apache
Groups: php.notes 
Request: Send a blank email to php-notes+get-45417@lists.php.net to get a copy of this message
Just removing the read right for Directories will not solve all the problems : If the user is using a well-known PHP Application which always stores it's database password in a well known file, it is easy to deduct the name of the file !! As for Safemode, it disables features that are required for several programs. The only solution for the PHP module, would be to support Suexec, which could be made optional... But at least, *nix installtion COULD be made more secure... I know I certainly use suexec for Perl, but the only way to do so for PHP is running it as a CGI, which is not a practical solution... -- http://www.php.net/manual/en/security.apache.php http://master.php.net/manage/user-notes.php?action=edit+30410 http://master.php.net/manage/user-notes.php?action=delete+30410 http://master.php.net/manage/user-notes.php?action=reject+30410

« previous php.notes (#45417) next »