note 15023 modified in security.apache by mfischer

From: Date: Fri, 31 May 2002 16:17:13 +0000
Subject: note 15023 modified in security.apache by mfischer
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-31298@lists.php.net to get a copy of this message
[ED note: it's not advised to enable ext/posix in an environments where security is a concern, this is also noted in the manual at php.net/posix ] Using posix_kill() function you can kill the child servers of others vhosts. (httpd) If you use safe_mode_exec_dir to restrict a path for exec programs... and use the htdocs as restricted path, the user can upload a sh binary and exec anything. The best solution is modify suexec.c and make a chroot to restricted envs... one for each vhost. --was-- Using posix_kill() function you can kill the child servers of others vhosts. (httpd) If you use safe_mode_exec_dir to restrict a path for exec programs... and use the htdocs as restricted path, the user can upload a sh binary and exec anything. The best solution is modify suexec.c and make a chroot to restricted envs... one for each vhost. http://www.php.net/manual/en/security.apache.php

« previous php.notes (#31298) next »