Date: Tue, 18 Mar 2003 10:49:18 -0500 From: Bill Moran <wmoran@potentialtech.com> To: Socketd <db@traceroute.dk> Cc: questions@freebsd.org Subject: Re: Insecure PHP installation Message-ID: <3E773FFE.5020700@potentialtech.com> In-Reply-To: <20030318154203.GI136@main> References: <20030318122217.GA136@main> <3E77139F.10003@potentialtech.com> <20030318130958.GC136@main> <3E772622.6030205@potentialtech.com> <20030318154203.GI136@main>
next in thread | previous in thread | raw e-mail | index | archive | help
Socketd wrote: > On 2003.03.18 14:58 Bill Moran wrote: > >> The way to do that would be to install PHP from downloaded source and see >> whether or not the permissions were still a problem. If you don't do it, >> someone else will have to in order to verify. > > Ok, will do that...... Actually ... in case you didn't see the other post, someone else has already verified that it's a PHP issue and not a FreeBSD one: > I just took a look at my freebsd box which has php installed from ports and > also a solaris box I have which had php installed from source. Both of them > have the same permissions which include: > > -rwxrwxrw- 1 root other 9290 Jan 6 13:57 pear > -rw-rw-rw- 1 root other 7719 Jan 6 13:57 HTTP.php > -rw-rw-rw- 1 root other 7279 Jan 6 13:57 Mail.php > -rw-rw-rw- 1 root other 28562 Jan 6 13:57 PEAR.php > -rw-rw-rw- 1 root other 14780 Jan 6 13:57 System.php > > etc. > > So it's a PHP issue, not a freebsd ports issue. > > --- > Matt (matt@xtaz.co.uk) He didn't say whether or not he was contacting the PHP people, but somebody should. >>> and therefore I wrote dirk@freebsd.org (and since he haven't written >>> back, now you). >> >> How long ago did you contact him? Sometimes it takes a few days for >> people to reply. > > It has been over a week since the first mail. Hmmm ... we'll that's longer than I would normally wait. I only asked because some people are far more impatient than that. -- Bill Moran Potential Technologies http://www.potentialtech.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3E773FFE.5020700>