#23277 [Opn->Bgs]: Apache safe_mode and open_basedir not enough
| From: | sniper@php.net | Date: | Mon, 21 Apr 2003 14:58:51 +0000 |
| Subject: | #23277 [Opn->Bgs]: Apache safe_mode and open_basedir not enough | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-37976@lists.php.net to get a copy of this message | ||
ID: 23277
Updated by: sniper@php.net
Reported By: flatface at flatface dot net
-Status: Open
+Status: Bogus
Bug Type: Program Execution
Operating System: *nix
PHP Version: 4.3.0
New Comment:
Not PHP problem.
Previous Comments:
------------------------------------------------------------------------
[2003-04-18 23:24:28] flatface at flatface dot net
I'm sorry for addressing it here, but I can't find anywhere else to put
it. I sysadmin a system with 1200 users, and I can't seem to find the
appropriate security to apply with php. suexec is fine with this shared
resoruce server, but with open_basedir, the most I can do is disallow
viewing of files below the script's location. With safe_mode on, it
goes overboard and disables a LOT of important functions that people
use (e.g. shell_exec), and even when people create files, it's still
chowned by apache and not the user. If mod_php could act a bit more
like suexec and run as the user in mod_php.
This is on php 4.3.0 on Gentoo Linux.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23277&edit=1