Quantcast
Channel: Why is PHP open_basedir not considered a security model - Server Fault
Viewing all articles
Browse latest Browse all 3

Answer by Segfault for Why is PHP open_basedir not considered a security model

$
0
0

Seems the reason for the disclaimer is that there are ways to break out of the open_basedir rule. I would still use it on a shared host but don't count on it as your only security. Also have each virtual host owned by a different user and run the apache process under that user account for the scripts on that host.

To your more general question though, I do think the age of shared hosting is almost over. Virtual host technology has advanced to the point that a shared host is almost useless.


Viewing all articles
Browse latest Browse all 3

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>