Re: Securing php: ezpublish

2004-09-06 Thread John Summerfield
Jonas Smedegaard wrote: Why, you might ask, did I not simply drop it below /var/www as everybody else? Because my job as package maintainer is not only to "throw something into the system", but also maintain package upgrades. What ever I "throw in", I must also maintain. So what I did was to only p

Re: Securing php: ezpublish

2004-09-01 Thread Jonas Smedegaard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01-09-2004 05:44, John Summerfield wrote: | I'm setting up some CMS software I found at ez.no. There's a Debian | package, but it's old and non-trivial to set up, so I've downloaded the | tarball from ez.no. The Debian package in testing/unstable is

Securing php: ezpublish

2004-08-31 Thread John Summerfield
I'm setting up some CMS software I found at ez.no. There's a Debian package, but it's old and non-trivial to set up, so I've downloaded the tarball from ez.no. The instructions say to configure php with safe_mode off. That doesn't excite me very much: I know little about PHP, but it sounds to m