Bug #3450: Secuity Bug

From: Date: Thu, 10 Feb 2000 18:06:41 +0000
Subject: Bug #3450: Secuity Bug
Groups: php.dev 
Request: Send a blank email to php-dev+get-15363@lists.php.net to get a copy of this message
From: argus@sover.net Operating system: BSDI 4.1 PHP version: 3.0.14 PHP Bug Type: Other Bug description: Secuity Bug We have php 3.0.14 running on a server with 1000+ virtual domains on it. Apache is running suexec so that cgi scripts run as the user. The system is also has quotas. A user called foo runs a php3 script that writes a file in his home directory. The user can write a file any place on the server. I thought about changing the doc_root to something, but each domain's doc root is in a very different location. The file is NOT owned by the user and therefor does NOT go against their quota. The file is owned by the user who the web server is running under (in our case www). This account (www) does not have quotas, and concievably foo could write a log file that could fill up the hard drive in a very short amount of time. Is there a way to make php scripts run as a user, the way suexec does? Is there a way that doc_root can be defined for each and every virtual domain? I really don't want to run php as a CGI, it defeats the purpose in my mind.

« previous php.dev (#15363) next »