note 26284 deleted from security.apache by nlopess
| From: | nlopess@php.net | Date: | Tue, 13 Jan 2004 15:21:44 +0000 |
| Subject: | note 26284 deleted from security.apache by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-63447@lists.php.net to get a copy of this message | ||
Note Submitter: live_beer@hotmail.com
----
I just wanted to make a comment related to securing files on a virtual host.
The system I was running scripts on was running in safe mode, and jailed the scripts to the virtual
server. As well, I had only FTP access which showed only a restricted amount of the server. The PHP
system was secure, and for 1 minute I thought so were my scripts and their contents.
The flaw was, like most servers, PHP is hardly the only thing running. Less then 2 minutes later I
was browsing other virtual hosts with a Perl script.
I know this is not a weakness with PHP, but someone with bad intentions doesnt care how they read
the database passwords from your PHP script, they just care that they can. The moral is you can lock
the front door, deadbolt and nail it shut, but its all for no good if the back door is open. When
considering security of your scripts, it is system security, not just PHP security that you need to
be concerned about.