note 15856 added to features.safe-mode

From: Date: Fri, 05 Oct 2001 14:42:47 +0000
Subject: note 15856 added to features.safe-mode
Groups: php.notes 
Request: Send a blank email to php-notes+get-18602@lists.php.net to get a copy of this message
OK - How to let uses make file uploads work in safe mode (icky!!!) ================================== We create a script which can be run in safe mode which runs as SETUID root which can chown a file in /tmp/ to any user and one to remove it afterwards (as php won't clean it up:) in the phpconf I add: php_admin_value safe_mode_exec_dir /usr/local/apache/phpsafebin/ Then add two scripts owned by root and setuid. These are: settmpowner -------------------- #!/usr/bin/perl -T unless( $ARGV[0] =~ m/^([a-z0-9]+)$/ ) { print "[settmpowner Bad USERNAME: \"$ARGV[1]\" ]\n"; exit 1; } my $owner = $1; unless( $ARGV[1] =~ m#^/tmp/([A-Za-z0-9]+)$# ) { print "[settmpowner Bad FILENAME: \"$ARGV[2]\" ]\n"; exit 1; } my $filename = "/tmp/$1"; delete $ENV{PATH}; my $cmd = "/bin/chown $owner $filename"; $cmd; my $cmd = "/bin/chmod a+wr $filename"; $cmd; -------------------------------- and rmtmp: ---------------------------------- #!/usr/bin/perl -T unless( $ARGV[0] =~ m#^/tmp/([A-Za-z0-9]+)$# ) { print "[rmtmp Bad FILENAME: \"$ARGV[2]\" ]\n"; exit 1; } my $filename = "/tmp/$1"; delete $ENV{PATH}; $cmd = "rm -f $filename"; $cmd; ------------------------------ The user then puts in their php script: system("settmpowner rdt199 $form_data"); to take ownership. Now they can read the file! At the end they MUST run system("rmtmp $form_data"); to clean up. This is not exactly a good solution, but it works. I think this does not create a security hole (but it's setuid root so probably does <sigh>) -- http://www.php.net/manual/en/features.safe-mode.php http://master.php.net/manage/user-notes.php?action=edit+15856 http://master.php.net/manage/user-notes.php?action=delete+15856 http://master.php.net/manage/user-notes.php?action=reject+15856

« previous php.notes (#18602) next »