Posted by Sensei on 08/03/06 16:57
On 2006-08-02 19:58:34 +0200, Miguel Cruz <spam@admin.u.nu> said:
>> <?
>> system('rm -rf /home/userThatIhate/www/*');
>> ?>
>>
>>
>> Is anyone aware of a possible solution about this problem?
>
> Disable system() and similar functions. You will not have security in a
> multi-untrusted-user environment when running PHP as an Apache module
> unless you do this.
Do you have any link that shows how to disable particular functions?
How's the granularity that I can apply --- and that you suggest?
--
Sensei <senseiwa@mac.com>
The optimist thinks this is the best of all possible worlds.
The pessimist fears it is true. [J. Robert Oppenheimer]
Navigation:
[Reply to this message]
|