#22410 [Bgs]: broader apache-php security options

From: Date: Wed, 30 Apr 2003 16:41:13 +0000
Subject: #22410 [Bgs]: broader apache-php security options
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38845@lists.php.net to get a copy of this message
ID: 22410 Updated by: rasmus@php.net Reported By: greg at laundrymat dot tv Status: Bogus Bug Type: Feature/Change Request Operating System: redhat 7.0 PHP Version: 4.3.0 New Comment: You can't use disable_functions on a per-dir basis because it is impossible to implement in an efficient manner. safe_mode already addresses this issue with its safe_mode_exec() dir. I am sorry if you feel this is too restrictive, but there is simply no way to make open_basedir restrictions apply to arbitrary scripts a user might run. Use safe-mode or set up a jailed configuration with individual instances of Apache listening on separate ports with a reverse proxy out front directing port 80 requests to the appropriate internal port. Previous Comments: ------------------------------------------------------------------------ [2003-04-30 11:26:23] wez@php.net Tried: php_admin_value disable_functions "system,exec" On a per directory basis? ------------------------------------------------------------------------ [2003-04-30 11:20:20] greg at laundrymat dot tv Will someone please address this security issue. It's huge! ------------------------------------------------------------------------ [2003-02-25 03:05:43] greg at laundrymat dot tv I really think there needs to be a way to prohibit system() ticker, or exec() on a per directory basis via the apache conf file. Safe mode is too restrictive and open_basedir doesn't work with these commands. Either make open base_dir actually work on all functions or create a way to shut these functions or any fuction off on a per directory basis. Its really is a must. I have a site that gives clients ftp access, A script could read the majority of the files on my server using the ticker and the vi commands. Thanks Greg Greenhaw ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=22410&edit=1

« previous php.bugs (#38845) next »