Permissions NOBODY

From: Date: Tue, 07 Nov 2000 16:50:51 +0000
Subject: Permissions NOBODY
Groups: php.general 
Request: Send a blank email to php-general+get-24126@lists.php.net to get a copy of this message
I've got a question about permissions, let me start off by saying i'm very new to php on linux, i usually use it on windows, however i've seen the light. so far it's been a breeze using linux and i feel like i'm on solid ground. However i've got a problem, i'm uploading files through a php script, when the file uploads it's owned by nobody/nobody. and i put them into a /backup direcotry sorta speak, it's in my webserver root. so it's accessible through the web. now, my thinking is that i need permission to write a file into my /backup directory in order to copy, ok, so this is a potential security risk tho right? i can't allow poeple to write to that directory. so what i have figured out is that what if when i upload a file, i programmically switch the permissions on the direcotry to allow writing, write hte file. and seal it back up. great, when i do this with php, i can't switch the permissions becuase php runs as nobody/nobody and nobody has no permissions. so i opened up my http directory to allow writing, and made a php script to recreate the /backup direcotry so it's owned by nobody.. made a new script to change it's permissions on the fly. .PERFECT.. so i can change the permissions on this directory with great ease, however.. my question is, does this leave me open for problems? seeing as how this directory is owned by nobody, does this mean that even tho the permissions are set to seal it up from people. does this mean ANYBODY can change these permissions and potentially cuase havoc? i just wanna upload files and be secure about it using php. if this is the wrong way to upload using php, can someone point me in a direction to do this securely? Thank you Ryan Sexton

« previous php.general (#24126) next »