From owner-freebsd-questions Tue Mar 18 5:59: 5 2003 Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1B5EE37B401 for ; Tue, 18 Mar 2003 05:59:04 -0800 (PST) Received: from pa-plum1b-166.pit.adelphia.net (pa-plum1b-122.pit.adelphia.net [24.53.161.122]) by mx1.FreeBSD.org (Postfix) with ESMTP id E510343FAF for ; Tue, 18 Mar 2003 05:59:02 -0800 (PST) (envelope-from wmoran@potentialtech.com) Received: from potentialtech.com (working [172.16.0.95]) by pa-plum1b-166.pit.adelphia.net (8.12.7/8.12.7) with ESMTP id h2IDx1Tb011717; Tue, 18 Mar 2003 08:59:01 -0500 (EST) (envelope-from wmoran@potentialtech.com) Message-ID: <3E772622.6030205@potentialtech.com> Date: Tue, 18 Mar 2003 08:58:58 -0500 From: Bill Moran User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.2.1) Gecko/20030301 X-Accept-Language: en-us, en MIME-Version: 1.0 To: Socketd Cc: freebsd-questions@freebsd.org Subject: Re: Insecure PHP installation References: <20030318122217.GA136@main> <3E77139F.10003@potentialtech.com> <20030318130958.GC136@main> In-Reply-To: <20030318130958.GC136@main> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG Socketd wrote: > On 2003.03.18 13:39 Bill Moran wrote: > >>> I have a FreeBSD 4.7-p7 computer with mod_php 4.3.1 installed and >>> several files are world writable, also a script /usr/local/bin/pear, >>> so I hope someone can do something about this or tell me that it is >>> supposed to be like this. >> >> Have you tried installing mod_php from source to see if it uses the same >> permissions? >> If it does, then you need to contact the PHP people. > > I installed from /usr/ports/www/mod_php4 (make install clean). I have > verified that I am not the only one with this problem. Before contacting > php.net, I wanted to make sure that the problem wasn't only on FreeBSD The way to do that would be to install PHP from downloaded source and see whether or not the permissions were still a problem. If you don't do it, someone else will have to in order to verify. > and therefore I wrote dirk@freebsd.org (and since he haven't written > back, now you). How long ago did you contact him? Sometimes it takes a few days for people to reply. -- Bill Moran Potential Technologies http://www.potentialtech.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message