Req #67712 [NEW]: Option to disable php_engine if file owner uid == getuid for webserver security
| From: | phpbugreq dot fileowner at sub dot noloop dot net | Date: | Wed, 30 Jul 2014 06:24:49 +0000 |
| Subject: | Req #67712 [NEW]: Option to disable php_engine if file owner uid == getuid for webserver security | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-186873@lists.php.net to get a copy of this message | ||
From: phpbugreq dot fileowner at sub dot noloop dot net
Operating system: UNIX
PHP version: Irrelevant
Package: Apache2 related
Bug Type: Feature/Change Request
Bug description:Option to disable php_engine if file owner uid == getuid for webserver security
Description:
------------
This is a simple feature request that might improve security for hosts
configured with a run-of-the-mill apache2+mod_php "LAMP stack":
I propose a new option in php.ini, for example "exec_deny_fileowner_self
= On" (default "Off").
If set, when starting to execute a script, the PHP engine checks the
script's file owner uid on disk against the currently running process'
uid. If they match, execution is disabled.
The idea is to prevent exploits in upload directories. A file upload via
some PHP script would normally be written to disk with a unix file owner
set to that of the webserver (for example "nobody" or "www-data"). A
subsequent request to execute the uploaded file will then fail, because
the file's owner uid is equal to the current uid of the executing apache
process.
It should be sufficient to perform the check only on the main script
file before execution starts; included/required files can probably be
skipped.
This would be very useful for hosting setups where PHP applications are
deployed by regular users onto a common apache2+mod_php setup. Of
course, it would break things like wordpress plugin installations
andauto-update (which requires the files to be writeable by the web
server), in which case the option should be kept disabled.
I'm aware that apache can be configured to disable PHP conditionally on
directories etc, but it can be easy to miss a location with many
virtualhosts and sites on a server. A simple optional setting like this
could arguably prevent a lot of common exploits for a relatively low
performance hit of a single file stat per script.
--
Edit bug report at https://bugs.php.net/bug.php?id=67712&edit=1
--