Re: Deny Access To configuration file using php scripts

Jan Urbancik <[email protected]>
Newsgroups gmane.comp.security.linux
Organization Web4All Technologies, s.r.o.
Message-ID <1109750357.17566.15.camel@debian>
Hi. 

My question is, if there is some patch, or workaround for php to allow
exec functions only for SOME apache virtual hosts... disable_functions
directive can not be overwritten via php_admin_value directive in
httpd.conf :-(

Jan

On Ut, 2005-03-01 at 18:58 -0500, Suramya Tomar wrote:
> Hi,
> 
> > Hello i have a web server and i have a major problem
> > some of my users are trying to find my pass for my mysql database.
> 
> My first suggestion would be to warn these users that this is not 
> allowed and ban them from the system if they persist.
> 
> > the first thing they do is a
> > system ('cat /var/www/path to config file');
> > inside a php script
> 
> 
> There are a couple of things you can try, First you can use apache 
> directives to deny access to the file. To do that add the following text 
> to the httpd.conf file:
> 
> <Files ~ "\.inc$">
>    Order allow, deny
>    Deny from all
> </Files>
> 
> This would prevent all files with the .inc extension from being viewed 
> via the web.
> 
> The second thing I would suggest is to disable access to the system() 
> function unless you really really need it. You can do that in the 
> php.ini file by using the disable_functions directive. It allows you to 
> define a comma-delimited list of functions to be disabled within PHP. 
> (http://www.onlamp.com/pub/a/php/2001/02/15/php_admin.html)
> 
> Hope this helps.
> 
> - Suramya
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.