note 73932 added to function.system

From: Date: Fri, 16 Mar 2007 04:28:14 +0000
Subject: note 73932 added to function.system
Groups: php.notes 
Request: Send a blank email to php-notes+get-124499@lists.php.net to get a copy of this message
I am in need of some security advice. I want to be able to automate the process of setting up a virtual host when someone registers for our web hosting service. I have thought about it for some time, and searched Google to my wit's end resulting in no good conclusions. The best way I figured out to accomplish this so far is: 1. Pass the user's domain_name variable from a php script to a bash script & execute that script via shell_exec("/home/scripts/create_virtualhost.sh $domain"); (Or one of the other variants of shell_exec ie.system(), exec(), passthrough(), etc; I'm having problems figuring out the difference between the various ones) 2. In that bash script, I add the user via adduser $domain... 3. Create the virtual host include file with the $domain variable filled into the necessary spots within that file. 4. restart apache Now I think this means that I would have to give the user 'nobody' sudo privileges to run the adduser command...and whatever other commands I decide need to go into the bash script. Now this seems like a terrible security risk. I would have to of course require a password for nobody to sudo. This password could either be stored in plain text inside the bash script, or perhaps I could have the script read the password from an encrypted file stored in some other location. (I'm not familiar enough with bash scripts to know how to do this or if its even possible, maybe with perl?). Of course even then that password file would have to be accessible by nobody in order for it to work. Maybe I could specify the command to read the password file as one of the commands nobody can run with sudo. Would this be secure? I would have the utmost gratitude for any help on this, as I am perplexed. ---- Server IP: 216.194.113.175 Probable Submitter: 66.68.169.33 ---- Manual Page -- http://www.php.net/manual/en/function.system.php Edit -- https://master.php.net/note/edit/73932 Del: integrated -- https://master.php.net/note/delete/73932/integrated Del: useless -- https://master.php.net/note/delete/73932/useless Del: bad code -- https://master.php.net/note/delete/73932/bad+code Del: spam -- https://master.php.net/note/delete/73932/spam Del: non-english -- https://master.php.net/note/delete/73932/non-english Del: in docs -- https://master.php.net/note/delete/73932/in+docs Del: other reasons-- https://master.php.net/note/delete/73932 Reject -- https://master.php.net/note/reject/73932 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#124499) next »