miva-security and user-downgrade scheme in php

From: Date: Sun, 06 Feb 2000 02:45:29 +0000
Subject: miva-security and user-downgrade scheme in php
Groups: php.dev 
Request: Send a blank email to php-dev+get-15232@lists.php.net to get a copy of this message
hello. in front of all: sorry for my bad english, i'm still learning ;-) but here is the messi ;-) ... --- AddType application/x-httpd-Miva .mv .hts Action application/x-httpd-Miva /cgi-miva/miva ScriptAlias /cgi-miva/miva/ /usr/local/miva/cgi-bin/miva/ --- ^-- this is the part you need for adding miva-support to apache (without suexec). whenever a .mv-file becomes accessed (e.g. throught http://www.foo.com/test.mv) the miva-binary gets started, runs several security-checks (read about it at http://www.miva.com/docs/mvadmin.html - Chapter: Miva Security System) like suexec, downgrades itself to the user who owns the .mv-file and begins execution. also you can define a directory where you can't go lower (like the doc_root in safe_mode). the miva-binary is owned by root and 'chmod 4755 miva'. this way i just need one miva-binary for all virtual-hosts. nevertheless every file created by the miva-script is owned by the user who owns the .mv-file. that way system quotas are working well. you even haven't to use #!-lines within the script. i tried the same with the cgi-version of php3... --- AddType application/x-httpd-php .mv .hts Action application/x-httpd-php /cgi-miva/php ScriptAlias /cgi-php/php/ /usr/local/miva/cgi-php/php3/ --- but php3 goes and interprets itself :( with the module-version, per-virtualhost-doc-roots and safe-mode every file created by the script is owned by the user running apache (of course). is there there a special reason why the way how miva handles executing isn't implemented in php? it would be a cool thing to run the php-scripts with the right uid (and gid?) so that files created by the script are owned by the right uid with the only need of one binary. i think this would be a really secure (even if not the really fast) and easy to admin way how to run php-scripts with several users on one machine. even because it is quite a normal to not have a #!-line in every script and so moving from the module-version to this would make no difference for the users. what do you think about it? thanks in advance and once more sorry for my english. i hope you all will understand what i mean ;-) greetings daniel

« previous php.dev (#15232) next »