Re: Permissions on uploaded files (Unix)

From: Date: Mon, 06 Nov 2000 18:23:34 +0000
Subject: Re: Permissions on uploaded files (Unix)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23940@lists.php.net to get a copy of this message
Actually, putting the nobody user in a common group is not a good idea. The nobody user is designed to have almost no read or write permissions to any files. You should make a www user, and have apache run as that. On Sun, 5 Nov 2000, jeremy brand wrote: > Kilian, > > Chown will not work at all. Most likely your webserver is running as > the user "nobody" or "www" or some other non-root user. The only user > that can change owners from themselves to someone else is root. PHP > or not, you just can't do that in UNIX. > > You might want to set up a common group that your webserver and > webmaster are part of. (see /etc/group and /etc/passwd). This would > seem to be the appropriate for what you need to accomplish. > > You could make a webedit group. Then make "nobody" and your webmaster > both part of it. > > Then, your perms on the file can be 0664 or 0775, yet still not > allowing "other" (everyone) else on your system access to the files. > This is still not completely optimal because your webserver can still > read/write/execute these files, and if your webserver was compromised > or you have a piece of exploitable code in your docroot things could > get messy. However, your webserver is the one that put the files > there in the first place, so if you allow that to happen, then this > solution doesn't downgrade that trust or security. > > I'm a complete security freak. (Sorry if I'm making things > difficult). > > :) > -jeremy brand > _______________________________________________________________________ > GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9 > _ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html for > more __ > > On Sun, 5 Nov 2000, Kilian wrote: > > > Date: Sun, 5 Nov 2000 20:10:39 +0100 > > From: Kilian <kil@bunny.ch> > > To: jeremy brand <jeremy@nirvani.net> > > Subject: Re: [PHP] Permissions on uploaded files (Unix) > > > > jeremy brand [jeremy@nirvani.net] wrote: > > > > Thanks very much for your reply! > > > > > You are playing under normal UNIX rules. I'm not saying this is > > > ideal (because it's not) or that I recomend it (because I don't) , but > > > it will work. You can make the choice if you want to risk security > > > over what you need to accomplish. > > > > > > After you upload your file, you can run the chmod() php function and > > > change the perms so that "other" can write to the file as well. Using > > > perms 0777 or 0666 will allow your webmaster (or anyone on that > > > system) to change those files. > > > > OK, what about > > > > system("chown <user> $file_name"); > > > > ? Even more insecure? > > > > -- Kilian > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#23940) next »