note 15856 added to features.safe-mode
| From: | chris-php at totl dot net | Date: | Fri, 05 Oct 2001 14:42:47 +0000 |
| Subject: | note 15856 added to features.safe-mode | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-18602@lists.php.net to get a copy of this message | ||
OK - How to let uses make file uploads work in safe mode (icky!!!)
==================================
We create a script which can be run in safe mode which runs as SETUID root which can chown a file in
/tmp/ to any user and one to remove it afterwards (as php won't clean it up:)
in the phpconf I add:
php_admin_value safe_mode_exec_dir /usr/local/apache/phpsafebin/
Then add two scripts owned by root and setuid. These are:
settmpowner
--------------------
#!/usr/bin/perl -T
unless( $ARGV[0] =~ m/^([a-z0-9]+)$/ )
{
print "[settmpowner Bad USERNAME: \"$ARGV[1]\" ]\n";
exit 1;
}
my $owner = $1;
unless( $ARGV[1] =~ m#^/tmp/([A-Za-z0-9]+)$# )
{
print "[settmpowner Bad FILENAME: \"$ARGV[2]\" ]\n";
exit 1;
}
my $filename = "/tmp/$1";
delete $ENV{PATH};
my $cmd = "/bin/chown $owner $filename";
$cmd;
my $cmd = "/bin/chmod a+wr $filename";
$cmd;
--------------------------------
and rmtmp:
----------------------------------
#!/usr/bin/perl -T
unless( $ARGV[0] =~ m#^/tmp/([A-Za-z0-9]+)$# )
{
print "[rmtmp Bad FILENAME: \"$ARGV[2]\" ]\n";
exit 1;
}
my $filename = "/tmp/$1";
delete $ENV{PATH};
$cmd = "rm -f $filename";
$cmd;
------------------------------
The user then puts in their php script:
system("settmpowner rdt199 $form_data");
to take ownership. Now they can read the file!
At the end they MUST run
system("rmtmp $form_data");
to clean up.
This is not exactly a good solution, but it works. I think this does not create a security hole (but
it's setuid root so probably does <sigh>)
--
http://www.php.net/manual/en/features.safe-mode.php
http://master.php.net/manage/user-notes.php?action=edit+15856
http://master.php.net/manage/user-notes.php?action=delete+15856
http://master.php.net/manage/user-notes.php?action=reject+15856