Bug #17911: users can view other user's web files through apache/php rights
| From: | tpalanga at hotmail dot com | Date: | Fri, 21 Jun 2002 19:49:18 +0000 |
| Subject: | Bug #17911: users can view other user's web files through apache/php rights | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-11738@lists.php.net to get a copy of this message | ||
From: tpalanga@hotmail.com
Operating system: Linux
PHP version: 4.1.2
PHP Bug Type: Apache related
Bug description: users can view other user's web files through apache/php rights
Hi.
Suppose we have a dedicated web server with 100 (or more) users. We
configure Apache so it will see every user's web files.
So we have user x and user y, User x cannot see or read the y's web files
or other files, but he is smart and somehow finds a mode to break into y's
web (especially in the case with /home/y/public_html setting --- every
user knows that user xxyy has an public_html in his home dir, so he
exploits it). How ? By Apache's rights. Does Apache have the rights to
read ALL USERS web files ? YES.
So x makes a browsing system and he uses Apache's rights to read ALL
USERS web files for reading y's web files. So x reads x's config.php (or
anything else) and he finds out the database user and pass. What next ?
So, I tink it's a bad thing (in fact it's a major security problem) for
php and Apache to use general rights for every user. Can Apache be
configured as an user-level multi-user-threaded server or this is a
SECURITY BUG ?
I think someone (at least PHP&Apache) cares.
Best regards
Tudor Palanga.
--
Edit bug report at http://bugs.php.net/?id=17911&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17911&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17911&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17911&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17911&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17911&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17911&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17911&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17911&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17911&r=globals