iNET Interactive - Online Advertising Agency
          
FreeWebHostingTalk Forums  
Quick Links
Find a Host » HOST QUOTE | ISPcheck.com
 
 
Go Back   FreeWebHostingTalk > Other Forums > FreeWebHostingTalk Lounge > PHP Safemode For Subdirectories

Reply
 
Thread Tools
Old 03-15-2006, 03:04 PM   #1
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 545

ZendURL is offline
Default PHP Safemode For Subdirectories
Is there anyway (preferably using .htaccess) to put php into safemode for all subdirectories (although not the root folder).
Also would this be enough to secure my website from hackers?

Also, since I am testing on a shared hosting package, there is no .htaccess file. Is there any way to get a .htaccess file onto my shared server?

Thanks!
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 04-05-2006, 06:09 PM   #2
jcink
Senior Member
 
Join Date: Sep 2005
Posts: 141

jcink is offline
Default
I know the date is old but if you're still having trouble or you used this method:

Are you saying you're using shared hosting and you host your users in their own folder on the shared host? Using htaccess to turn on safe mode in the folders wouldn't be safe enough, because people can do "../../" still in PHP and go above their folders. This is provided that your shared provider doesnt have open_basedir on. I mean, sure, permissions can be set, but still... some forums/scripts require stuff to be 777 so those users can get easily hacked.

I think.
Reply With Quote
Old 04-05-2006, 09:26 PM   #3
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 545

ZendURL is offline
Default
I am using a shared host, and I can host users in a subdirectory/folder on my domain name (hosted under my shared host).

I am required to have 777 permissions for the script to work. My script also utilizes url_fopen, so it is hard to set up any safety precautions.
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 04-05-2006, 11:16 PM   #4
jcink
Senior Member
 
Join Date: Sep 2005
Posts: 141

jcink is offline
Default
[code removed]

Last edited by jcink : 04-06-2006 at 01:16 AM.
Reply With Quote
Old 04-06-2006, 12:03 AM   #5
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 545

ZendURL is offline
Default
I put in the code and it gave me every folder and file that is on the main site (not in any subdirectories.)

So I know I am at risk... what do I do now (since I need those 777 permissions)
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 04-06-2006, 01:18 AM   #6
jcink
Senior Member
 
Join Date: Sep 2005
Posts: 141

jcink is offline
Default
oof.

Removed code so nobody reading this uses it on you.

Um. You need to talk to your hosting provider. You can't fix it from your end. PMed you with exact details to keep it off this board
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Advertisement:
 
     
 
 
 

Copyright © 2005-2007, FreeWHT.Com. All Rights Reserved.   Advertise on FreeWHT

Related iNET Interactive Sites:
Web Hosting Talk | Hosting Catalog | Hosting Tech | Hot Scripts

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.