Re: system level adduser

From: Date: Tue, 20 Jun 2000 23:45:00 +0000
Subject: Re: system level adduser
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-2396@lists.php.net to get a copy of this message
In article <4.3.1.2.20000615202109.00a93260@mailhost.sparknet.net>, john.hogan@sparknet.net (John Hogan) wrote: > We're creating a webmail application using U-Wash IMAP. The user fills out > a signup form to get an account. We want to add the user in real time, > giving them access to their account immediately. > > The best idea right now is to loop through the /etc/passwd file, looking > for the existence of a system username. If the selected name is not on the > list, we'd like to add it (probably using 'system()'). > > Would anyone care to comment on the security and procedure of adding system > users from a php script? Bad Idea (tm). But others are convinced it's okay if you do all sorts of things, like pipe the new user names into a database, and then run cron to add them. How this helps security, I'll never understand. (And it's been explained to me several times here.) Oh yeah, system() probably won't let you add stuff to /etc/passwd, at least not easily. "If you're not *SURE* it's safe, you don't know enough yet to implement it." This topic has been discussed a whole lot in the archives. -- Richard Lynch | If this was worth $$$ to you, buy a CD US Customer Support Director | from one of the artists listed here: Zend Technologies USA | http://www.L-I-E.com/artists.htm http://www.zend.com | (this has nothing to do with Zend, duh!)

« previous php.general (#2396) next »