Re: Permissions on uploaded files (Unix)

From: Date: Sun, 05 Nov 2000 19:34:03 +0000
Subject: Re: Permissions on uploaded files (Unix)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23800@lists.php.net to get a copy of this message
Kilian, Chown will not work at all. Most likely your webserver is running as the user "nobody" or "www" or some other non-root user. The only user that can change owners from themselves to someone else is root. PHP or not, you just can't do that in UNIX. You might want to set up a common group that your webserver and webmaster are part of. (see /etc/group and /etc/passwd). This would seem to be the appropriate for what you need to accomplish. You could make a webedit group. Then make "nobody" and your webmaster both part of it. Then, your perms on the file can be 0664 or 0775, yet still not allowing "other" (everyone) else on your system access to the files. This is still not completely optimal because your webserver can still read/write/execute these files, and if your webserver was compromised or you have a piece of exploitable code in your docroot things could get messy. However, your webserver is the one that put the files there in the first place, so if you allow that to happen, then this solution doesn't downgrade that trust or security. I'm a complete security freak. (Sorry if I'm making things difficult). :) -jeremy brand _______________________________________________________________________ GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9 _ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html for more __ On Sun, 5 Nov 2000, Kilian wrote: > Date: Sun, 5 Nov 2000 20:10:39 +0100 > From: Kilian <kil@bunny.ch> > To: jeremy brand <jeremy@nirvani.net> > Subject: Re: [PHP] Permissions on uploaded files (Unix) > > jeremy brand [jeremy@nirvani.net] wrote: > > Thanks very much for your reply! > > > You are playing under normal UNIX rules. I'm not saying this is > > ideal (because it's not) or that I recomend it (because I don't) , but > > it will work. You can make the choice if you want to risk security > > over what you need to accomplish. > > > > After you upload your file, you can run the chmod() php function and > > change the perms so that "other" can write to the file as well. Using > > perms 0777 or 0666 will allow your webmaster (or anyone on that > > system) to change those files. > > OK, what about > > system("chown <user> $file_name"); > > ? Even more insecure? > > -- Kilian >

« previous php.general (#23800) next »