Re: system level adduser
| From: | (Richard Lynch) | Date: | Tue, 20 Jun 2000 23:45:00 +0000 |
| Subject: | Re: system level adduser | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2396@lists.php.net to get a copy of this message | ||
In article <4.3.1.2.20000615202109.00a93260@mailhost.sparknet.net>,
john.hogan@sparknet.net (John Hogan) wrote:
> We're creating a webmail application using U-Wash IMAP. The user fills out
> a signup form to get an account. We want to add the user in real time,
> giving them access to their account immediately.
>
> The best idea right now is to loop through the /etc/passwd file, looking
> for the existence of a system username. If the selected name is not on the
> list, we'd like to add it (probably using 'system()').
>
> Would anyone care to comment on the security and procedure of adding system
> users from a php script?
Bad Idea (tm).
But others are convinced it's okay if you do all sorts of things, like
pipe the new user names into a database, and then run cron to add them.
How this helps security, I'll never understand. (And it's been explained
to me several times here.)
Oh yeah, system() probably won't let you add stuff to /etc/passwd, at
least not easily.
"If you're not *SURE* it's safe, you don't know enough yet to implement
it."
This topic has been discussed a whole lot in the archives.
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)