note 43201 added to ref.errorfunc
| From: | php-general at lists dot php dot net | Date: | Mon, 14 Jun 2004 00:49:56 +0000 |
| Subject: | note 43201 added to ref.errorfunc | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-71022@lists.php.net to get a copy of this message | ||
"For example, on my system apache runs as the user nobody so I must make sure that the file I
specified for error_log is owned by nobody, or world writable."
Ah, another security conscious web programmer is born. Log files must _never_ be world writable.
Never. Stop and think about it for a moment. You are putting a world writable file in a world
accessible location. That means that anyone in the world can write to it. Disk space is finite, so
if someone really wanted to be nasty they could fill up that log file, and your disk. If your
system isn't partitioned correctly (and a lot aren't these days) this will not only take
down your web site, but also your entire server.
Taking a mere second to do a 'chown nobody:nobody <logfile>; chmod 600
<logfile>' will not only keep your web server up and running a lot longer, it will also
help you keep your job. :)
----
Manual Page -- http://www.php.net/manual/en/ref.errorfunc.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+43201
Delete -- http://master.php.net/manage/user-notes.php?action=delete+43201&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+43201&report=yes
Search -- http://master.php.net/manage/user-notes.php