#22410 [Bgs]: broader apache-php security options
| From: | rasmus@php.net | Date: | Wed, 30 Apr 2003 16:41:13 +0000 |
| Subject: | #22410 [Bgs]: broader apache-php security options | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38845@lists.php.net to get a copy of this message | ||
ID: 22410
Updated by: rasmus@php.net
Reported By: greg at laundrymat dot tv
Status: Bogus
Bug Type: Feature/Change Request
Operating System: redhat 7.0
PHP Version: 4.3.0
New Comment:
You can't use disable_functions on a per-dir basis because it is
impossible to implement in an efficient manner.
safe_mode already addresses this issue with its safe_mode_exec() dir.
I am sorry if you feel this is too restrictive, but there is simply no
way to make open_basedir restrictions apply to arbitrary scripts a user
might run. Use safe-mode or set up a jailed configuration with
individual instances of Apache listening on separate ports with a
reverse proxy out front directing port 80 requests to the appropriate
internal port.
Previous Comments:
------------------------------------------------------------------------
[2003-04-30 11:26:23] wez@php.net
Tried:
php_admin_value disable_functions "system,exec"
On a per directory basis?
------------------------------------------------------------------------
[2003-04-30 11:20:20] greg at laundrymat dot tv
Will someone please address this security issue. It's huge!
------------------------------------------------------------------------
[2003-02-25 03:05:43] greg at laundrymat dot tv
I really think there needs to be a way to prohibit system()
ticker, or exec() on a per directory basis via the apache
conf file. Safe mode is too restrictive and open_basedir
doesn't work with these commands. Either make open
base_dir actually work on all functions or create a way to
shut these functions or any fuction off on a per directory
basis.
Its really is a must. I have a site that gives clients ftp
access, A script could read the majority of the files on my
server using the ticker and the vi commands.
Thanks
Greg Greenhaw
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=22410&edit=1