note 45536 added to ref.errorfunc

From: Date: Fri, 10 Sep 2004 00:55:13 +0000
Subject: note 45536 added to ref.errorfunc
Groups: php.notes 
Request: Send a blank email to php-notes+get-76366@lists.php.net to get a copy of this message
A rather smug individual opined: "Ah, another security conscious web programmer is born." Said individual then blessed us with his/her brilliance: "You are putting a world writable file in a world accessible location. That means that anyone in the world can write to it." Really? Say in php.ini I have error_log set to '/var/log/php/errors', and that furthermore the file is world writeable. You know where it is, and everybody can write to it, so go ahead, fill it up. Be my guest. Have at it. Of course, like anybody with half a clue I put the log file outside the Web tree, so you can't get to it, can you? Well, I suppose I could give you an account on my server... but that's not likely to happen, is it? Let's follow that thought a little, though. In your infinite wisdom you've also ignored the fact that hundreds of thousands of PHP sites are run on shared hosts which don't allow their users access to system utilities, so changing the owner or group of the file isn't possible. These people have the choice of making their log file world writeable or using some methodology which gives their PHP scripts their user privileges; that is, a choice between having a file accessible only to other users on their server (if they know where to look for it) or giving the world full access to their account if an exploitable flaw is found in PHP or a script they're using. At one large host I'm aware of, dozens of user accounts are cracked every week due to poorly written PHP scripts, while instances of users on a server interfering with other users are almost unheard of. Now, which would you say is the "security conscious" choice? ---- Manual Page -- http://www.php.net/manual/en/ref.errorfunc.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+45536 Delete -- http://master.php.net/manage/user-notes.php?action=delete+45536&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+45536&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#76366) next »