Req #67712 [Com]: Option to disable php_engine if file owner uid == getuid for webserver security

From: Date: Sun, 02 Feb 2020 19:40:24 +0000
Subject: Req #67712 [Com]: Option to disable php_engine if file owner uid == getuid for webserver security
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225307@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67712&edit=1 ID: 67712 Comment by: bugreports at gmail dot com Reported by: phpbugreq dot fileowner at sub dot noloop dot net Summary: Option to disable php_engine if file owner uid == getuid for webserver security Status: Suspended Type: Feature/Change Request Package: Apache2 related Operating System: UNIX PHP Version: Irrelevant Block user comment: N Private report: N New Comment: don't bring back safe_mode which brought more problems as it ever solved 10 years after we got rid of it https://www.php.net/manual/en/features.safe-mode.php Previous Comments: ------------------------------------------------------------------------ [2020-02-02 17:56:40] cmb@php.net This feature requires discussion on the internals mailing list, and potentially the RFC process[1]. For the time being, I'm suspending this ticket. [1] <https://wiki.php.net/rfc/howto> ------------------------------------------------------------------------ [2014-07-30 06:24:48] phpbugreq dot fileowner at sub dot noloop dot net Description: ------------ This is a simple feature request that might improve security for hosts configured with a run-of-the-mill apache2+mod_php "LAMP stack": I propose a new option in php.ini, for example "exec_deny_fileowner_self = On" (default "Off"). If set, when starting to execute a script, the PHP engine checks the script's file owner uid on disk against the currently running process' uid. If they match, execution is disabled. The idea is to prevent exploits in upload directories. A file upload via some PHP script would normally be written to disk with a unix file owner set to that of the webserver (for example "nobody" or "www-data"). A subsequent request to execute the uploaded file will then fail, because the file's owner uid is equal to the current uid of the executing apache process. It should be sufficient to perform the check only on the main script file before execution starts; included/required files can probably be skipped. This would be very useful for hosting setups where PHP applications are deployed by regular users onto a common apache2+mod_php setup. Of course, it would break things like wordpress plugin installations andauto-update (which requires the files to be writeable by the web server), in which case the option should be kept disabled. I'm aware that apache can be configured to disable PHP conditionally on directories etc, but it can be easy to miss a location with many virtualhosts and sites on a server. A simple optional setting like this could arguably prevent a lot of common exploits for a relatively low performance hit of a single file stat per script. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67712&edit=1

« previous php.bugs (#225307) next »