Re: Re: file upload, again
| From: | Grant Johnson | Date: | Wed, 14 Nov 2001 16:25:23 +0000 |
| Subject: | Re: Re: file upload, again | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-14325@lists.php.net to get a copy of this message | ||
Look in you apache.conf file and find out what user the web server runs as, then give that user the right to write to that directory, probably through a group used for nothing else is most secure.
Brian Mauter wrote:
To get around this, I made a small shell script which runs as root. The php page calls the script via the system call. All the shell script does is move a specific file from tmp to a specific location. I'm probably asking for someone to exploit it, but I don't know exactly what they can do. -Brian