note 28867 deleted from features.safe-mode by cmb
| From: | cmb@php.net | Date: | Tue, 13 Oct 2020 20:04:39 +0000 |
| Subject: | note 28867 deleted from features.safe-mode by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-215594@lists.php.net to get a copy of this message | ||
Note Submitter: gtg782a at mail dot gatech dot edu
----
zebz: The user would not be able to create a directory outside the namespace where he/she would be
able to modify its contents. One can't create a directory that becomes apache-owned unless one
owns the parent directory.
Another security risk: since files created by apache are owned by apache, a user could call the
fputs function and output PHP code to a newly-created file with a .php extension, thus creating an
apache-owned PHP script on the server. Executing that apache-owned script would allow the script to
work with files in the apache user's namespace, such as logs. A solution would be to force
PHP-created files to be owned by the same owner/group as the script that created them. Using
open_basedir would be a likely workaround to prevent ascension into uncontrolled areas.