#23277 [Opn->Bgs]: Apache safe_mode and open_basedir not enough

From: Date: Mon, 21 Apr 2003 14:58:51 +0000
Subject: #23277 [Opn->Bgs]: Apache safe_mode and open_basedir not enough
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-37976@lists.php.net to get a copy of this message
ID: 23277 Updated by: sniper@php.net Reported By: flatface at flatface dot net -Status: Open +Status: Bogus Bug Type: Program Execution Operating System: *nix PHP Version: 4.3.0 New Comment: Not PHP problem. Previous Comments: ------------------------------------------------------------------------ [2003-04-18 23:24:28] flatface at flatface dot net I'm sorry for addressing it here, but I can't find anywhere else to put it. I sysadmin a system with 1200 users, and I can't seem to find the appropriate security to apply with php. suexec is fine with this shared resoruce server, but with open_basedir, the most I can do is disallow viewing of files below the script's location. With safe_mode on, it goes overboard and disables a LOT of important functions that people use (e.g. shell_exec), and even when people create files, it's still chowned by apache and not the user. If mod_php could act a bit more like suexec and run as the user in mod_php. This is on php 4.3.0 on Gentoo Linux. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23277&edit=1

« previous php.bugs (#37976) next »