Re: [PHP3] does PAM lib PHP3 interface exist ?
| From: | Chad Cunningham | Date: | Fri, 14 Jan 2000 16:58:34 +0000 |
| Subject: | Re: [PHP3] does PAM lib PHP3 interface exist ? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14636@lists.php.net to get a copy of this message | ||
Steve Langasek wrote:
> At some point or another, something is going to be running as root on the
> system in order for the user to be able to change their password.
Sure, but passwd has extra checks that I want. A PHP script could change
passwords by just sticking things in the password file, but that means
your script has to have write access to the password file. You could
suid the script, but there are ways to exploit this regardless of how
many steps you take, plus on my system the shadow password file is not
writeable by anyone, including root. So you can use the passwd program
non interactively from php, but that means you have to be running it as
root to change other users passwords. Running passwd as root subjects
you to far less security checks on my system, such as the fact that you
can change any users passwords, and it permits you to use undesireable
passwords. By using expect, I can su to the user who wants to change
their password. That way they can't change any other users passwords
(unless they already know then, in which case they could just ssh
in...), and they have the other security checks (not choosing similar
passwords, no dictionary words, etc).
> (Unless you
> have a system that uses a network password db that doesn't require root
> access, but that's not the common case.) And every additional layer you put
> between the user and PAM necessarily restricts the system's flexibility. Yes,
> you also gain some security by doing so, but no more security than with a
> carefully constructed PHP script. There's nothing wrong in principle with an
> suid php script. They could cause a lot of damage if written carelessly but
> properly audited, this could be a very useful tool.
Who cares about flexibility, I want users to be able to change their
password from the web without compromising my system. I'm not a clever
hacker, but I have the feeling that running anythig via the web as root
is more of a hole than I want in my system. And in the case of letting a
user change a password, I see no need to do this as root when doing it
as the user works perfectly fine.
--
Chad Cunningham
ccunning@math.ohio-state.edu
"I'll tell you what kind of guy I was. If you ordered a boxcar full of
sons-of-bitches and opened the door and only found me inside, you could
consider the order filled."
-Robert Mitchum