Re: Permissions on uploaded files (Unix)
| From: | Carey Tilden | Date: | Mon, 06 Nov 2000 18:23:34 +0000 |
| Subject: | Re: Permissions on uploaded files (Unix) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23940@lists.php.net to get a copy of this message | ||
Actually, putting the nobody user in a common group is not a good idea.
The nobody user is designed to have almost no read or write permissions to
any files. You should make a www user, and have apache run as that.
On Sun, 5 Nov 2000, jeremy brand wrote:
> Kilian,
>
> Chown will not work at all. Most likely your webserver is running as
> the user "nobody" or "www" or some other non-root user. The only user
> that can change owners from themselves to someone else is root. PHP
> or not, you just can't do that in UNIX.
>
> You might want to set up a common group that your webserver and
> webmaster are part of. (see /etc/group and /etc/passwd). This would
> seem to be the appropriate for what you need to accomplish.
>
> You could make a webedit group. Then make "nobody" and your webmaster
> both part of it.
>
> Then, your perms on the file can be 0664 or 0775, yet still not
> allowing "other" (everyone) else on your system access to the files.
> This is still not completely optimal because your webserver can still
> read/write/execute these files, and if your webserver was compromised
> or you have a piece of exploitable code in your docroot things could
> get messy. However, your webserver is the one that put the files
> there in the first place, so if you allow that to happen, then this
> solution doesn't downgrade that trust or security.
>
> I'm a complete security freak. (Sorry if I'm making things
> difficult).
>
> :)
> -jeremy brand
> _______________________________________________________________________
> GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9
> _ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html for
> more __
>
> On Sun, 5 Nov 2000, Kilian wrote:
>
> > Date: Sun, 5 Nov 2000 20:10:39 +0100
> > From: Kilian <kil@bunny.ch>
> > To: jeremy brand <jeremy@nirvani.net>
> > Subject: Re: [PHP] Permissions on uploaded files (Unix)
> >
> > jeremy brand [jeremy@nirvani.net] wrote:
> >
> > Thanks very much for your reply!
> >
> > > You are playing under normal UNIX rules. I'm not saying this is
> > > ideal (because it's not) or that I recomend it (because I don't) , but
> > > it will work. You can make the choice if you want to risk security
> > > over what you need to accomplish.
> > >
> > > After you upload your file, you can run the chmod() php function and
> > > change the perms so that "other" can write to the file as well. Using
> > > perms 0777 or 0666 will allow your webmaster (or anyone on that
> > > system) to change those files.
> >
> > OK, what about
> >
> > system("chown <user> $file_name");
> >
> > ? Even more insecure?
> >
> > -- Kilian
> >
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>