risks of using posix_setuid posix_setgid

From: Date: Tue, 31 Oct 2000 00:37:35 +0000
Subject: risks of using posix_setuid posix_setgid
Groups: php.general 
Request: Send a blank email to php-general+get-22793@lists.php.net to get a copy of this message
im trying to write a server-wide file control panel for my virtual hosts. problem is that i am also using suexec to take advantage of running CGI's under the specific usernames of the clients. the control panel itself is on a seperate secure port (https://domain:99) , password protected by mod_auth_mysql. all functions that relate to modifyig the server, adding/removing domains, sub-domains, DNS issues, proftpd FTP accounts are handled by MySQL. QmailAdmin handles all email Adding a user account will always be left to manually enter one on the server. the major problem i am having is switching to the proper user (returned by $PHP_AUTH_USER), in the scripts. i could use the cgi versions and use suexec to change to the right user, but that would causs for a HUGE makeover of my current apache control panel config file and $PHP_AUTH_ vars arent avilable. i will also be implementing sessions support later on. what i need to know, is what user could i set apache to run as, still be safe in terms of root, but allow posix_set*id ?? or what i need to do to create a user that can setuid to another user (that isnt root). im using redhat 6.1 , all of my user accounts are username/user group/cust user id's are >500 , group is 500 thank you, bjorn

« previous php.general (#22793) next »