Re: Deny Access To configuration file using php scripts

From: Josh Sholes (sholes_at_zedxinc.com)
Date: 03/01/05

  • Next message: Suramya Tomar: "Re: Deny Access To configuration file using php scripts"
    To: focus-linux@securityfocus.com
    Date: Tue, 1 Mar 2005 14:31:39 -0500
    
    

    On Tuesday 01 March 2005 12:54, raT wrote:
    > Hello i have a web server and i have a major problem
    >
    > some of my users are trying to find my pass for my mysql database.
    >
    > the first thing they do is a
    > system ('cat /var/www/path to config file');
    > inside a php script
    >
    > my problem is to deny this file from being read throu the script since
    > the apache deamon runs as nobody
    > and it has to have read permision to the configuration file.
    >
    > my users have shell acount and can create files in the public_html folder.
    > any help?
    > snif!

    I'll leave the web security half of this question to the
    web-security-knowledgable types, and just answer the "any help" part:

    Problem users should find their accounts locked. Zero-tolerance.
    Anything less, IMHO, is making yourself an accessory to the hijacking of your
    own server.

    > thanks in advance.

    -- 
    Josh Sholes
    System Administrator
    ZedX Inc.
    sholes@zedxinc.com
    

  • Next message: Suramya Tomar: "Re: Deny Access To configuration file using php scripts"

    Relevant Pages

    • RE: Deny Access To configuration file using php scripts
      ... >> Hello i have a web server and i have a major problem ... > There are a couple of things you can try, First you can use apache ... not stop a php script from accessing the files. ...
      (Focus-Linux)
    • Re: Suggestions on creating a File Download area
      ... filename will be able to download the file without paying you anything. ... as the web server wouldn't go out of the /var/www/html ... A php script can read a file outside the document-root, ... use fpassthru() function, of course you can use any of the other file read ...
      (alt.php)
    • Re: A password problem
      ... "Mark Wooding" wrote in message ... > matter for Eve to write a PHP script which runs any arbitrary program ... But if Eve *can't* get the password in clear text (i.e. the web ... If we get rid of the bugs we've identified with web server security, ...
      (sci.crypt)
    • Re: link DB record through browser...
      ... The web browser sends a request to the web server, ... runs the PHP script which sends a query ... http://mindprod.com Java custom programming, consulting and coaching. ...
      (comp.lang.java.databases)
    • Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous
      ... accessible location on the web server, then have all the pdf files outputed ... through a script such as a php script. ... personalized online radio with MSN Radio powered by Pandora. ...
      (Bugtraq)