Bug #16287 Updated: SUID for PHP scripts

From: Date: Tue, 26 Mar 2002 14:52:51 +0000
Subject: Bug #16287 Updated: SUID for PHP scripts
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-3394@lists.php.net to get a copy of this message
ID: 16287 Updated by: alan_k@php.net Reported By: luci@conexim.com.au -Status: Open +Status: Bogus Bug Type: Feature/Change Request Operating System: RH7.2 PHP Version: 4.1.2 New Comment: This is part of Apache &/or the web server responsiblity, doing it in PHP, would (apart from duplicate resources), be a bit security headache.. I believe it is a feature of Apache 2. If you are looking at cgi's, you could consider the php-cgiwrap that is available on the net somewhere. Its not really (AFAIK) ever going to be a php feature. Previous Comments: ------------------------------------------------------------------------ [2002-03-26 09:16:52] luci@conexim.com.au ooops should've changed the status before... ------------------------------------------------------------------------ [2002-03-26 09:12:48] luci@conexim.com.au Those functions are very good, except they cannot be used in a hosting context where the users are not root... There should be a mechanism like Apache has for .cgi's (per virtual host or location) or dynamically establishing the owner via the home directory lookup. ------------------------------------------------------------------------ [2002-03-26 09:08:19] hholzgra@php.net http://php.net/posix_setuid ------------------------------------------------------------------------ [2002-03-26 09:01:24] derick@php.net PHP already has functions to swap uids and guids, posix_* (see www.php.net/posix). Derick ------------------------------------------------------------------------ [2002-03-26 08:59:44] luci@conexim.com.au There is a need for suexec/suid type functionality for PHP scripts - switch of ownership conext in a secure environment. Is this going to happen? ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=16287&edit=1

« previous php.bugs (#3394) next »