Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
| From: | Mic Kaczmarczik | Date: | Wed, 22 Sep 1999 21:18:27 +0000 |
| Subject: | Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11216@lists.php.net to get a copy of this message | ||
>Hrm, but in safe-mode you can only exec() stuff from the
>safe-mode-exec-dir so I am not quite sure how you would launch this setuid
>program that you might have managed to create.
>
>Through cgi perhaps? I agree that we probably should have a look at
>safe-mode and chmod(), but I don't see a clear exploit here.
>
>-Rasmus
Fair question. To launch the setuid shell, you would need interactive
shell access to the Web server system. Not all sites allow this.
Plus, many sites mount all but a few system areas with a no-setuid
mount option. This further limits the potential problem. It's only
those sites that
1) use safe mode at all
2) allow interactive logins on the Web server
3) allow setuid execution of user-created files
that would have any particular concern about this. At my site
conditions #1 and #2 hold but not #3, since we mount almost everything
no-setuid. But all I have to do is forget the no-setuid mount during
a system migration or upgrade and I've potentially allowed access I am
going to some trouble to avoid by using safe mode in the first place.
Thanks for your response,
--mic--
-- Mic Kaczmarczik -- Unix Services -- UT Austin Academic Computing (ACITS) --