note 30410 added to security.apache
| From: | MartinPierre at rack1 dot php dot net | Date: | Mon, 17 Mar 2003 15:45:30 +0000 |
| Subject: | note 30410 added to security.apache | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-45417@lists.php.net to get a copy of this message | ||
Just removing the read right for Directories will not solve all the problems :
If the user is using a well-known PHP Application which always stores it's database password in
a well known file, it is easy to deduct the name of the file !!
As for Safemode, it disables features that are required for several programs.
The only solution for the PHP module, would be to support Suexec, which could be made optional...
But at least, *nix installtion COULD be made more secure...
I know I certainly use suexec for Perl, but the only way to do so for PHP is running it as a CGI,
which is not a practical solution...
--
http://www.php.net/manual/en/security.apache.php
http://master.php.net/manage/user-notes.php?action=edit+30410
http://master.php.net/manage/user-notes.php?action=delete+30410
http://master.php.net/manage/user-notes.php?action=reject+30410