PHP runs unser the user that apache runs under.
usually user www.
This user should be quite restricted in access rights, as apache is available to the grand public.
Make sure the few files and directories that you do let php write are owned by the apache-user.
Do not let php read/write from/to files that have access rights like 777 because that is quite dangerous.