Re: [PHP3] does PAM lib PHP3 interface exist ?

From: Date: Fri, 14 Jan 2000 17:09:00 +0000
Subject: Re: [PHP3] does PAM lib PHP3 interface exist ?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14637@lists.php.net to get a copy of this message
On Fri, 14 Jan 2000, Chad Cunningham wrote: > Sure, but passwd has extra checks that I want. A PHP script could change > passwords by just sticking things in the password file, but that means > your script has to have write access to the password file. You could > suid the script, but there are ways to exploit this regardless of how > many steps you take, plus on my system the shadow password file is not > writeable by anyone, including root. So you can use the passwd program > non interactively from php, but that means you have to be running it as > root to change other users passwords. Running passwd as root subjects > you to far less security checks on my system, such as the fact that you > can change any users passwords, and it permits you to use undesireable > passwords. By using expect, I can su to the user who wants to change > their password. That way they can't change any other users passwords > (unless they already know then, in which case they could just ssh > in...), and they have the other security checks (not choosing similar > passwords, no dictionary words, etc). All of these are checks that could be done very easily using PAM. > Who cares about flexibility, I want users to be able to change their > password from the web without compromising my system. I'm not a clever > hacker, but I have the feeling that running anythig via the web as root > is more of a hole than I want in my system. And in the case of letting a > user change a password, I see no need to do this as root when doing it > as the user works perfectly fine. *I* care about flexibility. :) I want both flexibility and security, and I mean to get it! :) If your current system works, and you're happy with it, then more power to you, but that's no reason to say that PHP *shouldn't* be allowed to run as root. -Steve Langasek postmodern programmer

« previous php.dev (#14637) next »