Reasons to use safe mode
| From: | Sam Jordan | Date: | Thu, 07 Dec 2000 10:09:29 +0000 |
| Subject: | Reasons to use safe mode | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-29084@lists.php.net to get a copy of this message | ||
Hello all
I'm working for an ISP and I'm currently preparing to give
users the possibilities to write and upload PHP scripts
themselves. We are using PHP 4.00.
I'd like to hear what is exactly the reason to use safe mode
in an environment, where php scripts are only executed by the
webserver (apache module) and not directly through the 'php'
executable.
My basic idea is, that every user, which writes php scripts,
is caged into its own home directory, and so doesn't have access
to anything which is located outside. The configuration parameter
'open_basedir' does this job well (at least I got the impression).
I'm currently trying to find out, what would happen if I would
disable safe mode, while keeping the open_basedir variable to
point to the users home directory. What sort of misuses/attacks
are thinkable in such an environment?
My main problem with the safe mode is, that the users can not
write any files with php, even not into their own directory tree.
Except if the scripts are chowned to the apache user, but this
is not a real option, because the rights of the scripts are
set to the FTP user after every re-upload. By disabling safe mode
I could set up a tmp directory belonging to the apache user, where
the users could write their files to. Additionally file upload
could be made working much easier.
Thanks for any comment (please write to sjo@spin.ch)
Sam Jordan