note 54858 added to features.safe-mode
| From: | jo at durchholz dot org | Date: | Mon, 18 Jul 2005 08:18:17 +0000 |
| Subject: | note 54858 added to features.safe-mode | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-92095@lists.php.net to get a copy of this message | ||
Note that safe mode is largely useless. Most ISPs that offer Perl also offer other scripting
languages (mostly Perl), and these other languages don't have the equivalent of PHP.
In other words, if PHP's safe mode won't allow vandals into your web presence, they will
simply use Perl.
Also, safe mode prevents scripts from creating and using directories (because they will be owned by
the WWW server, not by the user who uploaded the PHP script). So it's not only useless,
it's also a hindrance.
The only realistic option is to bugger the Apache folks until they run all scripts as the user
who's responsible for a given virtualhost or directory.
----
Manual Page -- http://www.php.net/manual/en/features.safe-mode.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+54858
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+54858&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+54858&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+54858&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+54858&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+54858&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+54858&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+54858&report=yes
Search -- http://master.php.net/manage/user-notes.php