iNET Interactive - Online Advertising Agency
          
FreeWebHostingTalk Forums  
Quick Links
Find a Host » HOST QUOTE | ISPcheck.com
 
 
Go Back   FreeWebHostingTalk > Main Forums > Running A Free Web Hosting Company > Ways or methods to secure PHP?

Reply
 
Thread Tools
Old 09-14-2004, 05:06 PM   #1
Mike_FWT
Junior Member
 
Join Date: Sep 2004
Location: Atlanta, GA
Posts: 29

Send a message via AIM to Mike_FWT
Mike_FWT is offline
Default Ways or methods to secure PHP?
Our custom-designed hosting environment had a major issue this weekend when a hacker was somewhat successful in deleting a number of user sites using a special PHP program. Everything has since been restored, but it's obviously frustrating to have to take these drastic measures.

We've made the decision to re-remove PHP access (we had just recently decided to allow it again after putting in some safeguards - these were subsequently worked around by this &&&hole) and as much as we hate to, it's a necessary evil at this point.

Anyone have any suggestions/methods to safeguard PHP on a large shared hosting system? Our system is highly customized (without giving too much away) and unique traditional username-based methods won't cut it. I'd be interested in some of your experiences and/or suggestions.

Thanks in advance...

Anyone familiar with someone who goes by the name of "The Turk HaCKer" or "dodo885"? I'd love five minutes alone with that guy...

dodo885
__________________
Mike_FWT | FreeWebTown.com Community
Extending the power of people online
Reply With Quote
Old 09-14-2004, 05:36 PM   #2
Odd Fact
Community Leader
 
Odd Fact's Avatar
 
Join Date: Sep 2004
Posts: 25

Odd Fact is offline
Default
Search over at WHT. I remember one of the host developing a safe mode alternative. Might have been Affordable Hosting.
__________________
Too much love drives a man insane!

Web Hosting Talk - Give it a try, you'll like it!
Reply With Quote
Old 09-15-2004, 01:38 AM   #3
Paul
Junior Member
 
Join Date: Sep 2004
Posts: 3

Paul is offline
Default
Hello
Here is a website with various ways to crash PHP:
http://ilia.ws/archives/5_Top_10_ways_to_crash_PHP.html
This proves that PHP is not safe straight out of the box. The shell_exec command looks extremely deadly and should definitely be disabled as it has the possibility to give complete control of the server to the user.
Reply With Quote
Old 09-15-2004, 01:56 AM   #4
JTY
Senior Member
 
JTY's Avatar
 
Join Date: Sep 2004
Location: Ellensburg, WA
Posts: 128

Send a message via ICQ to JTY Send a message via MSN to JTY
JTY is offline
Default
I would look into using safe_mode and setting open_base_dir.
__________________
John T. Yocum -- Fluid Hosting
Shared - VPS - Dedicated - Colocation
Reply With Quote
Old 09-21-2004, 04:12 AM   #5
freerackspace.org
Senior Member
 
Join Date: Sep 2004
Posts: 168

freerackspace.org is offline
Default
Try employing a top notch admin to secure the box as much as possible, put creative limits on the PHP use, and hope for the best. Make daily, weekly and monthly backups to another location, so you can always do a restore.
Reply With Quote
Old 09-21-2004, 04:14 AM   #6
monoxide
Junior Member
 
Join Date: Sep 2004
Posts: 21

monoxide is offline
Default
You need to disable functions in the php.ini and you need to install mod_security. This will stop most php hacks.

I hope this helps out.

Mod Edit: This forum is not for advertising/self-promotion.

Last edited by JTY : 09-22-2004 at 05:21 AM. Reason: Self-Promotion
Reply With Quote
Old 09-24-2004, 08:19 PM   #7
excelblue
Junior Member
 
Join Date: Sep 2004
Posts: 6

excelblue is offline
Default
Use different accounts for different users and only allow that user to have read access. Then, create a group for each user, and set a vhost for that user to use the group. You'd have to deal with subdomains, but oh well, they don't cost anything, do they?
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Advertisement:
 
     
 
 
 

Copyright © 2005-2007, FreeWHT.Com. All Rights Reserved.   Advertise on FreeWHT

Related iNET Interactive Sites:
Web Hosting Talk | Hosting Catalog | Hosting Tech | Hot Scripts

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.