Bug #16287 Updated: SUID for PHP scripts
| From: | daniel@php.net | Date: | Tue, 26 Mar 2002 16:06:45 +0000 |
| Subject: | Bug #16287 Updated: SUID for PHP scripts | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-3401@lists.php.net to get a copy of this message | ||
ID: 16287
Updated by: daniel@php.net
Reported By: luci@conexim.com.au
Status: Bogus
Bug Type: Feature/Change Request
Operating System: RH7.2
PHP Version: 4.1.2
New Comment:
There is no official solution for this. But you might want to read my
posting:
http://news.php.net/article.php?group=php.dev&article=81135
although there are some people who believe in the greater security of
mod_php as mod_php has no write access to the home directories of the
user.
feel free to contact me for further questions about php-cgiwrap by
private mail.
Previous Comments:
------------------------------------------------------------------------
[2002-03-26 09:52:50] alan_k@php.net
This is part of Apache &/or the web server responsiblity, doing it in
PHP, would (apart from duplicate resources), be a bit security
headache..
I believe it is a feature of Apache 2.
If you are looking at cgi's, you could consider the php-cgiwrap that is
available on the net somewhere.
Its not really (AFAIK) ever going to be a php feature.
------------------------------------------------------------------------
[2002-03-26 09:16:52] luci@conexim.com.au
ooops should've changed the status before...
------------------------------------------------------------------------
[2002-03-26 09:12:48] luci@conexim.com.au
Those functions are very good, except they cannot be used in a hosting
context where the users are not root...
There should be a mechanism like Apache has for .cgi's (per virtual
host or location) or dynamically establishing the owner via the home
directory lookup.
------------------------------------------------------------------------
[2002-03-26 09:08:19] hholzgra@php.net
http://php.net/posix_setuid
------------------------------------------------------------------------
[2002-03-26 09:01:24] derick@php.net
PHP already has functions to swap uids and guids, posix_* (see
www.php.net/posix).
Derick
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/16287
--
Edit this bug report at http://bugs.php.net/?id=16287&edit=1