Solved

Restricting PHP's disk access to its own virtual host

Posted on 2004-03-28
1
211 Views
Last Modified: 2013-12-15
I have this setup:

- Red Hat 7.2
- PHP 4 (Apache module)
- Apache 1.3 (running as nobody:nobody)
and several name-based virtual hosts running on this system using the same IP.

I would like to set it so that PHP scripts running on a certain virtual host cannot access the other host's disk structure. In this way, www.domain.com's scripts won't be able to snoop through www.otherdomain.com's files.

Is this possible at all?

(I don't mind using PHP's Safe Mode at all if required)

Thank you.
0
Comment
Question by:poisa
1 Comment
 
LVL 9

Accepted Solution

by:
Alf666 earned 200 total points
ID: 10703002
Yep. You have to use safe_mode.

safe_mode = on

Then in your <VirtualHost>:

php_admin_flag engine on
php_admin_value open_basedir "/<whatever>/domain.com/htdocs:/tmp"

This makes /tmp a common storing place.

You you could also have a tmp directory in each of your domains tree.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
digital ocean web console access ? does it use port 22 4 57
Zimbra on Amazon Linux help 7 115
centos commands 6 93
regular expression help for sed command 5 42
If you have a server on collocation with the super-fast CPU, that doesn't mean that you get it running at full power. Here is a preamble. When doing inventory of Linux servers, that I'm administering, I've found that some of them are running on l…
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question