<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Mon, 20 May 2013 11:05:36 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[PHP Security Blog: Open_basedir confusion]]></title>
      <guid>http://www.phpdeveloper.org/news/7283</guid>
      <link>http://www.phpdeveloper.org/news/7283</link>
      <description><![CDATA[<p>
<i>Stefan Esser</i> is trying to clear up some confusion in a <a href="http://blog.php-security.org/archives/72-Open_basedir-confusion.html">new post</a> to the PHP Security Blog today about his stand on enabling <a href="http://www.php.net/manual/en/features.safe-mode.php">open_basedir</a> on your PHP installation.
</p>
<blockquote>
From time to time I get the question why I recommend enabling <a href="http://www.php.net/manual/en/features.safe-mode.php">open_basedir</a> and on the other hand call it a solution flawed by design. This is actually a good question, because the untrained PHP user might get a little bit confused about this and might believe that I change my opinion on a daily basis.
</blockquote>
<p>
He <a href="http://blog.php-security.org/archives/72-Open_basedir-confusion.html">talks about</a> his reasoning - how it does it's job protecting PHP developers from being able to get to those file, but how it's also flawed with issues due to some 3rd party libraries that have their own problems.
</p>]]></description>
      <pubDate>Thu, 15 Feb 2007 07:42:00 -0600</pubDate>
    </item>
  </channel>
</rss>
