Re: security issue
| From: | Boian Bonev | Date: | Sat, 03 Feb 2001 14:19:08 +0000 |
| Subject: | Re: security issue | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-45667@lists.php.net to get a copy of this message | ||
hi,
or better if you have untrusted users who shall have php access, give them
cgi php and use apache's exec wrapper to setuid to user's uid and chroot to
her home dir.
if their count is not too big run their own web servers under their uids and
again chrooted to their home dirs. this is the best solution known by me.
b.
----- Original Message -----
From: "Chris Newbill" <cnewbill@onewest.net>
To: "Lou Spironello" <lrs@bigfoot.com>; <php-dev@lists.php.net>
Sent: Saturday, February 03, 2001 12:20 AM
Subject: RE: [PHP-DEV] security issue
> A good start would be to make sure the user your web server is running as
> cannot read the shadow file. Also that the permissions are set properly.
>
> Chris
>
> -----Original Message-----
> From: Lou Spironello [mailto:lrs@bigfoot.com]
> Sent: Friday, February 02, 2001 2:17 PM
> To: php-dev@lists.php.net
> Subject: [PHP-DEV] security issue
>
>
> <?php $a=
ls -R /; echo $a; ?>
> <?php $a=cat /etc/shadow; echo $a; ?>
> etc..
> Produces listing of the entire system and dump of the password file.
>
> This is a security hole.
>
> How can I prevent this?
>
> Lou.
>
>
>
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>