Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 18 Mar 2003 10:49:18 -0500
From:      Bill Moran <wmoran@potentialtech.com>
To:        Socketd <db@traceroute.dk>
Cc:        questions@freebsd.org
Subject:   Re: Insecure PHP installation
Message-ID:  <3E773FFE.5020700@potentialtech.com>
In-Reply-To: <20030318154203.GI136@main>
References:  <20030318122217.GA136@main> <3E77139F.10003@potentialtech.com> <20030318130958.GC136@main> <3E772622.6030205@potentialtech.com> <20030318154203.GI136@main>

next in thread | previous in thread | raw e-mail | index | archive | help
Socketd wrote:
> On 2003.03.18 14:58 Bill Moran wrote:
> 
>> The way to do that would be to install PHP from downloaded source and see
>> whether or not the permissions were still a problem.  If you don't do it,
>> someone else will have to in order to verify.
> 
> Ok, will do that......

Actually ... in case you didn't see the other post, someone else has already
verified that it's a PHP issue and not a FreeBSD one:

 > I just took a look at my freebsd box which has php installed from ports and
 > also a solaris box I have which had php installed from source. Both of them
 > have the same permissions which include:
 >
 > -rwxrwxrw-   1 root     other       9290 Jan  6 13:57 pear
 > -rw-rw-rw-   1 root     other       7719 Jan  6 13:57 HTTP.php
 > -rw-rw-rw-   1 root     other       7279 Jan  6 13:57 Mail.php
 > -rw-rw-rw-   1 root     other      28562 Jan  6 13:57 PEAR.php
 > -rw-rw-rw-   1 root     other      14780 Jan  6 13:57 System.php
 >
 > etc.
 >
 > So it's a PHP issue, not a freebsd ports issue.
 >
 > ---
 > Matt (matt@xtaz.co.uk)

He didn't say whether or not he was contacting the PHP people, but somebody
should.

>>> and therefore I wrote dirk@freebsd.org (and since he haven't written 
>>> back, now you).
>>
>> How long ago did you contact him?  Sometimes it takes a few days for
>> people to reply.
> 
> It has been over a week since the first mail.

Hmmm ... we'll that's longer than I would normally wait.  I only asked
because some people are far more impatient than that.

-- 
Bill Moran
Potential Technologies
http://www.potentialtech.com


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3E773FFE.5020700>