You are here: Re: PHP harm on WebDAV « PHP Programming Language « IT news, forums, messages
Re: PHP harm on WebDAV

Posted by Virginner on 12/17/05 11:54

"Sensei" <senseiwa@mac.com> wrote in message
news:44d09bd8$0$35076$4fafbaef@reader4.news.tin.it...
| Hi!
|
| I was wondering about the feasibility of having PHP safer than I can
| imagine right now.
|
| This is the situation. Apache with webdav enabled for all users in
| write mode. Let's say users have /home/username/www as their web sites.
| In order to make it work, every www must have write permission set to
| apache. This way people can upload their personal web sites via webdav.
|
| Since PHP scripts run with the same username as apache, something like
| this is possible:
|
| <?
| system('rm -rf /home/userThatIhate/www/*');
| ?>
|
|
| Is anyone aware of a possible solution about this problem?

Make sure safe_mode is on... ?

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация