Re: New security extension: scripthash
| From: | John Sutton | Date: | Sat, 09 Dec 2000 10:25:47 +0000 |
| Subject: | Re: New security extension: scripthash | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-40641@lists.php.net to get a copy of this message | ||
> > > protect. How does scripthash do it?
>
> Maybe I'm just slow, but I didn't quite get it.
> Apache generates a random secret at startup, right?
Yes. (And in v0.3 coming soon, optionally the secret is regenerated every X
seconds, just for those who are super paranoid. ;-)
> So the different apps (e.g. mysqlpassd) needs to know this secret
> to validate the requests, right?
Yes.
> So how is the secret shared between the apps and apache?
> And what prevents a third party application from doing the exact same
> thing to get the secret?
It's stored in a shared memory segment which is owned by root (or whoever
starts up apache) and has mode 600. So, only processes running as root can
read it EXCEPT for the apache children themselves. They can read it even
though they are running as uid nobody because the attach of the memory
segment survives the fork. This is the key to the whole thing.
> Some detailed issues though:
> * mysqlpasswd has nothing to do with mysql - maybe a different name
> would be better?
> * Could mysqlpassdbm replace the password file instead of changing it?
> Then it didn't have to stop mysqlpasswd while updating. It would be
> enough to HUP mysqlpasswd after updating the file - or even better,
> the deamon can stat the file and discovere it is updated itself.
> (or maybe even better, mysqlpasswd can compile the dbm file itself
> from a plaintext file, every time the file is updated - like sendmail
> does for it's aliases files).
> * the spec file should put the scripthash files in a seperate rpm
> from php itself - like the redhat rpm does with all the modules.
All your comments are perfectly valid but as you say yourself they are
matters of detail. I'm not inclined to put much more effort into it until
the "big guns" pass judgement on the basic security issues:
1) how safe is the secret?
2) how big do the secret and the random string need to be?
Once these matters are resolved, I'm hoping that the scripthash extension
itself might find its way into the base distribution, and the associated apps
will become PEAR "widgets"?
***************************************************
John Sutton
SCL Computer Services
URL http://www.scl.co.uk/
Tel. +44 (0) 1239 621021
***************************************************