Bug #13247 Updated: Move_uploaded_file set wrong user and wrong group
| From: | sander@php.net | Date: | Mon, 08 Oct 2001 12:58:28 +0000 |
| Subject: | Bug #13247 Updated: Move_uploaded_file set wrong user and wrong group | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-67533@lists.php.net to get a copy of this message | ||
ID: 13247
Updated by: sander
Reported By: linux@infomaniak.ch
Old Status: Feedback
Status: Closed
Bug Type: Unknown/Other Function
Operating System: Cobalt OS
PHP Version: 4.0.4pl1
New Comment:
No feedback. Unlikely to be a bug in PHP. Closing.
Previous Comments:
------------------------------------------------------------------------
[2001-09-11 10:29:21] hholzgra@php.net
i'm pretty sure php doesn't touch your file ownerships
more likely you have either root as primary group for
user apache in /etc/passwd or sicky bits set for the
directory ... ?
------------------------------------------------------------------------
[2001-09-11 09:23:06] linux@infomaniak.ch
Here is my configure line :
'./configure' '--with-mysql' '--with-gd' '--with-ttf'
'--enable-bcmath' '--enable-calendar'
'--enable-memory-limit' '--enable-safe-mode' '--with-imap'
'--enable-ftp' '--enable-sockets' '--with-apxs'
The script that is used is as simple as :
<?
@move_uploaded_file($file,
"/path/to/my/directory/filename");
?>
My Apache webserver runs as user and group httpd.
Now the really annoying thing is that whenever my customer
or myself upload a file, the uploaded file is correctly
moved but the ownership is set to httpd.root ( user httpd
and group root ) Now this is a real big problem for my (
even without considering the security hole it represents )
because my customers cannot manage to erase these files
anymore afterwards via FTP, because their uid will not let
them touch these files.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13247&edit=1