note 73932 added to function.system
| From: | james at janglin dot net | Date: | Fri, 16 Mar 2007 04:28:14 +0000 |
| Subject: | note 73932 added to function.system | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-124499@lists.php.net to get a copy of this message | ||
I am in need of some security advice. I want to be able to automate the process of setting up a
virtual host when someone registers for our web hosting service. I have thought about it for some
time, and searched Google to my wit's end resulting in no good conclusions. The best way I
figured out to accomplish this so far is:
1. Pass the user's domain_name variable from a php script to a bash script & execute that
script via
shell_exec("/home/scripts/create_virtualhost.sh $domain");
(Or one of the other variants of shell_exec ie.system(), exec(), passthrough(), etc; I'm having
problems figuring out the difference between the various ones)
2. In that bash script, I add the user via adduser $domain...
3. Create the virtual host include file with the $domain variable filled into the necessary spots
within that file.
4. restart apache
Now I think this means that I would have to give the user 'nobody' sudo privileges to run
the adduser command...and whatever other commands I decide need to go into the bash script. Now this
seems like a terrible security risk. I would have to of course require a password for nobody to
sudo. This password could either be stored in plain text inside the bash script, or perhaps I could
have the script read the password from an encrypted file stored in some other location. (I'm
not familiar enough with bash scripts to know how to do this or if its even possible, maybe with
perl?). Of course even then that password file would have to be accessible by nobody in order for it
to work. Maybe I could specify the command to read the password file as one of the commands nobody
can run with sudo. Would this be secure? I would have the utmost gratitude for any help on this, as
I am perplexed.
----
Server IP: 216.194.113.175
Probable Submitter: 66.68.169.33
----
Manual Page -- http://www.php.net/manual/en/function.system.php
Edit -- https://master.php.net/note/edit/73932
Del: integrated -- https://master.php.net/note/delete/73932/integrated
Del: useless -- https://master.php.net/note/delete/73932/useless
Del: bad code -- https://master.php.net/note/delete/73932/bad+code
Del: spam -- https://master.php.net/note/delete/73932/spam
Del: non-english -- https://master.php.net/note/delete/73932/non-english
Del: in docs -- https://master.php.net/note/delete/73932/in+docs
Del: other reasons-- https://master.php.net/note/delete/73932
Reject -- https://master.php.net/note/reject/73932
Search -- https://master.php.net/manage/user-notes.php