Permissions NOBODY
| From: | Ryan Sexton | Date: | Tue, 07 Nov 2000 16:50:51 +0000 |
| Subject: | Permissions NOBODY | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24126@lists.php.net to get a copy of this message | ||
I've got a question about permissions, let me start off by saying i'm very
new to php on linux, i usually use it on windows, however i've seen the
light. so far it's been a breeze using linux and i feel like i'm on solid
ground. However i've got a problem, i'm uploading files through a php
script, when the file uploads it's owned by nobody/nobody. and i put them
into a /backup direcotry sorta speak, it's in my webserver root. so it's
accessible through the web. now, my thinking is that i need permission to
write a file into my /backup directory in order to copy, ok, so this is a
potential security risk tho right? i can't allow poeple to write to that
directory. so what i have figured out is that what if when i upload a file,
i programmically switch the permissions on the direcotry to allow writing,
write hte file. and seal it back up. great, when i do this with php, i
can't switch the permissions becuase php runs as nobody/nobody and nobody
has no permissions. so i opened up my http directory to allow writing, and
made a php script to recreate the /backup direcotry so it's owned by
nobody.. made a new script to change it's permissions on the fly. .PERFECT..
so i can change the permissions on this directory with great ease, however..
my question is, does this leave me open for problems? seeing as how this
directory is owned by nobody, does this mean that even tho the permissions
are set to seal it up from people. does this mean ANYBODY can change these
permissions and potentially cuase havoc? i just wanna upload files and be
secure about it using php. if this is the wrong way to upload using php, can
someone point me in a direction to do this securely?
Thank you
Ryan Sexton