PHP:具有写权限的缓存文件夹的tcpdf安全注意事项
我已经在我的网络服务器上安装了 tcpdf 并使用它来生成 pdf 发票。它有一个缓存文件夹,我的网络服务器用户组 www-data 可以创建和删除文件。
黑客是否可以
a) 在该文件夹中创建文件并
b) 将它们作为 php 执行?
我应该将缓存文件夹移到 www 目录之外吗?我尝试 cd 进入该文件夹,但我自己的用户名出现权限错误,所以我想知道该步骤是否必要。
I have installed tcpdf on my web server and use it to generate pdf invoices. It has a cache folder and my web server user group www-data can create and delete files.
Could a hacker
a) create files in that folder and
b) execute them as php?
Should I move the cache folder outside of the www directory? I tried to cd into the folder but get a permission error with my own username, so I was wondering if that step is necessary.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
如果您没有对用户组进行任何更改,则 www-data 组仅用于记录目的,浏览器无法访问。数据用户将能够创建但不应该删除任何内容。但至于担心黑客访问您的网站,只要您没有更改该用户的任何权限即可。
If you have not made any changes to your user groups a www-data group is only used for logging purposes and is not able to accessed by the browser. The data user will be able to create but it should not be deleting anything. But as for worrying about hackers accessing your site as long as you have not changed any permissions for this user No.