i installed ispconfig and running very good. but i tested security system with c99shell.php security test script. but i can access all directories. for example / and others. but this must be only access this directory /var/www/web1/. what is my problem please help. thank you.
note: i researched may be this problem from open_basedir php.ini. or web1 apache conf
Last edited by kidalabama; 4th October 2008 at 22:12.
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
I think he is right.
But I'd guess here's a bit more needed. At one side to either drop open_basedir completely or the much better solution, to have a textfield where an admin may add specific path's for a web, where this web may get access too. E.g. when using pear's php_ajax package, which needs libraries from the general pear store on the server (which is placed differently depending on the used distro).
i added two times php_admin_value open_basedir ".$mod->system->server_conf["server_path_httpd_root"]."/"."web".$web["doc_id"]."
but all domains added php_admin_value open_basedir.
i dont want one domain add this code. how can i do this ?
i want all domains added except only one domain. but my code added all domains.
Last edited by kidalabama; 6th October 2008 at 13:45.
i am sending a php security control program. i can access all the other hosting and folders please help. and please test it is very bad sacurity risk.
for example i am open a host customer and this customer access all the other hosting it is very dangerous.
Recent comments
21 hours 40 min ago
1 day 7 hours ago
1 day 7 hours ago
1 day 11 hours ago
1 day 15 hours ago
1 day 16 hours ago
1 day 18 hours ago
2 days 4 hours ago
2 days 9 hours ago
2 days 10 hours ago