RE: [PHP] PHP User Permissions
| From: | Matthew Walker | Date: | Fri, 13 Sep 2002 20:55:06 +0000 |
| Subject: | RE: [PHP] PHP User Permissions | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-116312@lists.php.net to get a copy of this message | ||
And if you're running apache as root, you shouldn't be allowed to.
Apache should always be run as as nonpriviledged user.
On Fri, 2002-09-13 at 09:04, J Smith wrote:
>
> > A running script cannot change its own permissions
>
> If you mean can't change it's user ID and/or group ID, that isn't entirely
> true.
>
> If your script is being run as a privileged user on a UNIX system (usually
> root), you can change the user/group IDs of the process (either effective
> or real) with the POSIX extension. (posix_seteuid(), posix_setuid(), etc.)
>
> I haven't tried it from an Apache process, so I can't say if it will work
> from a web server (doubtful) but it does work for standalone scripts from
> the CGI/CLI.
>
> J
>
>
> Jay Blanchard wrote:
>
> > [snip]
> > Does anyone know how to define a PHP script (within itself) to run as a
> > certain user. Currently my PHP scirpt runs as "nobody" and I need to
> > change the user it runs as temporarily to get certain permissions to
> > update a file.
> > [/snip]
> >
> > A running script cannot change its own permissions, and if accessed from
> > the browser will always run as Apache allows (which is generally
> > nobody/nogroudark_panda@hushmail.comp). What you need to do is change the permission/owner
> > of the
> > file that you're trying to update with either chown(), chmod(), or both.
> >
> > HTH!
> >
> > Jay
> >
> > Good Judgement comes from experience; experience comes from Poor Judgement
> >
> > *****************************************************
> > * Texas PHP Developers Conf Spring 2003 *
> > * T Bar M Resort & Conference Center *
> > * New Braunfels, Texas *
> > * Contact jay.blanchard@niicommunications.com *
> > * *
> > * Want to present a paper or workshop? Contact now! *
> > *****************************************************
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>