Re: Looking for general advice on security
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.lang.php archive

Re: Looking for general advice on security

From: Colin McKinnon <colin.thisisnotmysurname@ntlworld.deletemeunlessURaBot.com>
Date: Sun Apr 30 2006 - 23:21:20 CEST

Schraalhans Keukenmeester <firstname_DOT_lastname_AT_xs4all_DOT_nl> wrote:

> Gordon Burditt wrote:
>>>I'm designing a survey form page that will be fairly complex and am
<snip>
>> PHP pages (with an Apache PHP-module setup) have to be world-readable,
>> for Apache/PHP to use them.
>
> Not true, at least not on my FC4 box. I have my html & php files all set
> to:
>
> -rw-r----- 1 root apache 33 Apr 20 05:24 example.php
> -rw-r----- 1 root apache 817 Mar 06 11:32 index.html
>
> and they are served up nicely.

Yes, but I'm cringing even now with the thought that this is a response to a
thread about security.

(Chris Shiflett is often found hanging around when people are talking about
PHP security and has written some good articles on the subject - try Google
for specifics).

C.
Received on Mon May 1 03:08:05 2006