Req #67712 [Com]: Option to disable php_engine if file owner uid == getuid for webserver security
| From: | bugreports at gmail dot com | Date: | Sun, 02 Feb 2020 19:40:24 +0000 |
| Subject: | Req #67712 [Com]: Option to disable php_engine if file owner uid == getuid for webserver security | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225307@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67712&edit=1
ID: 67712
Comment by: bugreports at gmail dot com
Reported by: phpbugreq dot fileowner at sub dot noloop dot net
Summary: Option to disable php_engine if file owner uid ==
getuid for webserver security
Status: Suspended
Type: Feature/Change Request
Package: Apache2 related
Operating System: UNIX
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
don't bring back safe_mode which brought more problems as it ever solved 10 years after we got
rid of it
https://www.php.net/manual/en/features.safe-mode.php
Previous Comments:
------------------------------------------------------------------------
[2020-02-02 17:56:40] cmb@php.net
This feature requires discussion on the internals mailing list,
and potentially the RFC process[1]. For the time being, I'm
suspending this ticket.
[1] <https://wiki.php.net/rfc/howto>
------------------------------------------------------------------------
[2014-07-30 06:24:48] phpbugreq dot fileowner at sub dot noloop dot net
Description:
------------
This is a simple feature request that might improve security for hosts configured with a
run-of-the-mill apache2+mod_php "LAMP stack":
I propose a new option in php.ini, for example "exec_deny_fileowner_self = On" (default
"Off").
If set, when starting to execute a script, the PHP engine checks the script's file owner uid on
disk against the currently running process' uid. If they match, execution is disabled.
The idea is to prevent exploits in upload directories. A file upload via some PHP script would
normally be written to disk with a unix file owner set to that of the webserver (for example
"nobody" or "www-data"). A subsequent request to execute the uploaded file will
then fail, because the file's owner uid is equal to the current uid of the executing apache
process.
It should be sufficient to perform the check only on the main script file before execution starts;
included/required files can probably be skipped.
This would be very useful for hosting setups where PHP applications are deployed by regular users
onto a common apache2+mod_php setup. Of course, it would break things like wordpress plugin
installations andauto-update (which requires the files to be writeable by the web server), in which
case the option should be kept disabled.
I'm aware that apache can be configured to disable PHP conditionally on directories etc, but it
can be easy to miss a location with many virtualhosts and sites on a server. A simple optional
setting like this could arguably prevent a lot of common exploits for a relatively low performance
hit of a single file stat per script.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67712&edit=1