Window Server 2003 R2 x64 Std Apache/PHP/Tomcat Security



I have a Window Server 2003 R2 x64 Std and want to ask how to set Apache and PHP Security and Security of Tomcat.

In my installation with Apache 2 and PHP 5 is possible to make/list folder/files to C: root and every where in server.

How to I setup these user settings like there only to possible to make things above only in wanted folders and exec function can be used only for run chosen applications. I know how to set in php.ini that exec function is not possible and that php files can be ran only in chosen folders but that not fix everything. In my install Apache can but only configured folders to public by VirtualHost but PHP seems to can be do everything. So if I try to but non-configured folder to apache VirtualHost it tells me that there is not any read/write rights to this folder. That seems to work and Apache haves atomatically made security settings and user accounts.
.



Relevant Pages

  • [NT] Compromising IIS or Apache Servers Running PHP for Windows (Step-by-Step)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... compromise a host running only PHP and Apache or IIS under the Windows ... PHP version 4.1.1 under IIS ... We used the following installation procedure: ...
    (Securiteam)
  • Re: Window Server 2003 R2 x64 Std Apache/PHP/Tomcat Security
    ... and PHP Security and Security of Tomcat. ... In my installation with Apache 2 and PHP 5 is possible to make/list folder/files to C: root and every where in server. ... How to I setup these user settings like there only to possible to make things above only in wanted folders and exec function can be used only for run chosen applications. ...
    (microsoft.public.windows.server.security)
  • Re: setting file access permissions broken in XP
    ... the read-only attribute does not apply to folders in XP. ... I don't run Apache and am unclear ... web development and using Apache, then as I said before you need to ... I really can't help you with Apache or php. ...
    (microsoft.public.windowsxp.newusers)
  • Re: Intro To Hacking
    ... Read a comprehensive guide to FreeBSD, Apache, and PHP. ... For general security, Hacking Exposed 4 ... UC Berkeley ResComp ...
    (Security-Basics)
  • [NT] PHP Reveals True Path (OPTIONS)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... When a web administrator installs Apache with PHP and adds index.php to ... < HTTP/1.1 500 Internal Server Error ...
    (Securiteam)