9, January 2009

PHP safemode - webmaster forum

 
Webdigity webmaster forums
This forum shares its ad revenue with its members!
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: PHP safemode
« previous next »
Pages: [1] Print

Author Topic: PHP safemode  (Read 1115 times)
Supreme Overlord
***
Gender: Male
Posts: 149
910 credits
Members referred : 0


www.centos.org


« on: Feb 23, 2006, 10:57:33 AM »

Can anything bad happen running your server with PHP safe mode off? I am having a hard time getting vBulletin to work with safemode on. I keep getting errors when uploading avatars.
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 8357
43129 credits
Members referred : 3



« Reply #1 on: Feb 23, 2006, 10:59:49 AM »

It depends on your code.

If you execute exec() commands the you may have problems.

Also you should check if someone using your code can have read/write access to anywhere outside your www directory.

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy or twitter Visit through proxy

Last blog : Monetizing Old Posts
Supreme Overlord
***
Gender: Male
Posts: 149
910 credits
Members referred : 0


www.centos.org


« Reply #2 on: Feb 25, 2006, 03:26:57 AM »

I am running PHP with the following   disable_functions = "exec,system,passthru,readfile,shell_exec,escapeshellarg,escapeshellcmd,proc_close,proc_open,ini_alter,dl,popen,parse_ini_file,show_source,curl_exec"

Think I am safe?
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 8357
43129 credits
Members referred : 3



« Reply #3 on: Feb 25, 2006, 11:08:07 AM »

To be honest I never take a good look to this issue as the sites that I host in my own server are sites of my clients (meaning that none of them can upload a php file, all the updates are done through my cms)

Now the problem that I think you may have, is that the user will be able to view the code of your other sites, or even change it. php is running through the apache user, so it has actually access to the whole of the htdocs tree.

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy or twitter Visit through proxy

Last blog : Monetizing Old Posts
Supreme Overlord
***
Gender: Male
Posts: 149
910 credits
Members referred : 0


www.centos.org


« Reply #4 on: Feb 25, 2006, 05:59:17 PM »

I am the only user on the server, I am only running 2 websites on the server. 1 static website and my forum. The server is in the process of moving to the data center, It should be online monday. I am going to enable safemode again and mess with it some more. vBulletin is a pain in the rear, I have had nothing but problems getting it to work.
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 8357
43129 credits
Members referred : 3



« Reply #5 on: Feb 26, 2006, 11:47:31 AM »

If you are the only user in the server, then you don't really have to enable safe mode.

Safe mode is not protecting you from outside, but inside the server. I mean that safe mode can protect you from people that using the same server and upload their pages there.

If you plan not to share your server, then it is totally useless.

On the other hand, even if you plan to share it, you can allways enable it/disable on a per host basis.

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy or twitter Visit through proxy

Last blog : Monetizing Old Posts
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=1573
Tags : php forums vBulletin apache php safemode Bookmark this thread : Digg Del.icio.us Dzone more....

Topic sponsors:
Get a permanent link here for $1.99!


Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: PHP safemode
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Jan 09, 2009, 09:09:25 AM





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 38.657
Total Topics: 7.772
Total Members: 4.660
Tutorials : 56
Resources : 143
Designs : 220
Latest Member: mahendra

25 Guests, 3 Users online :

15 users online today:



Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2009 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.