Click here to get back home

Window Server 2003 R2 x64 Std Apache/PHP/Tomcat Security

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Window Server 2003 R2 x64 Std Apache/PHP/Tomcat Security Matti Kiviharju 01-14-2008
Posted by Matti Kiviharju on January 14, 2008, 4:54 am
Please log in for more thread options
I have a Window Server 2003 R2 x64 Std and want to ask how to set Apache
and PHP Security and Security of Tomcat.

In my installation with Apache 2 and PHP 5 is possible to make/list
folder/files to C: root and every where in server.

How to I setup these user settings like there only to possible to make
things above only in wanted folders and exec function can be used only
for run chosen applications. I know how to set in php.ini that exec
function is not possible and that php files can be ran only in chosen
folders but that not fix everything. In my install Apache can but only
configured folders to public by VirtualHost but PHP seems to can be do
everything. So if I try to but non-configured folder to apache
VirtualHost it tells me that there is not any read/write rights to this
folder. That seems to work and Apache haves atomatically made security
settings and user accounts.

Posted by Matti Kiviharju on January 16, 2008, 12:29 pm
Please log in for more thread options
Matti Kiviharju kirjoitti:
> I have a Window Server 2003 R2 x64 Std and want to ask how to set Apache
> and PHP Security and Security of Tomcat.
>
> In my installation with Apache 2 and PHP 5 is possible to make/list
> folder/files to C: root and every where in server.
>
> How to I setup these user settings like there only to possible to make
> things above only in wanted folders and exec function can be used only
> for run chosen applications. I know how to set in php.ini that exec
> function is not possible and that php files can be ran only in chosen
> folders but that not fix everything. In my install Apache can but only
> configured folders to public by VirtualHost but PHP seems to can be do
> everything. So if I try to but non-configured folder to apache
> VirtualHost it tells me that there is not any read/write rights to this
> folder. That seems to work and Apache haves atomatically made security
> settings and user accounts.


And the wath is problem? Apache works but with PHP I can run command
exec('format C:'); and then it is end ofthe story if I don't dissable
exec function on php.ini. That is not what I want. I want that format C:
is only able to run with admin account and PHP is always ran with
account that can not execute commands like format c:.

Similar ThreadsPosted
Determining Window Server 2003 Security Policy for US Office November 8, 2005, 11:19 am
Window Server 2003 RDP/DDE May 16, 2008, 3:07 pm
Password Security Policy for Local on Window 2003 March 14, 2008, 4:10 pm
cannot access web page on window 2003 server October 26, 2006, 9:51 pm
Window 2003: Dial-In->Remote Access Permission Default June 29, 2005, 3:33 pm
Role-based security from Windows Server 2003 Security Guide gives problems November 6, 2006, 8:00 am
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm
2003 IIS/OS Server Security May 16, 2006, 9:13 pm
Security Tab missing (Win 2003 Server) December 1, 2005, 7:40 pm
Windows 2003 server and VPN: Security(?) December 16, 2005, 4:20 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap