note 15023 modified in security.apache by mfischer
| From: | mfischer@php.net | Date: | Fri, 31 May 2002 16:17:13 +0000 |
| Subject: | note 15023 modified in security.apache by mfischer | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-31298@lists.php.net to get a copy of this message | ||
[ED note: it's not advised to enable ext/posix in an environments where security is a concern,
this is also noted in the manual at php.net/posix ]
Using posix_kill() function you can kill the child servers of others vhosts. (httpd)
If you use safe_mode_exec_dir to restrict a path for exec programs... and use the htdocs as
restricted path, the user can upload a sh binary and exec anything.
The best solution is modify suexec.c and make a chroot to restricted envs... one for each vhost.
--was--
Using posix_kill() function you can kill the child servers of others vhosts. (httpd)
If you use safe_mode_exec_dir to restrict a path for exec programs... and use the htdocs as
restricted path, the user can upload a sh binary and exec anything.
The best solution is modify suexec.c and make a chroot to restricted envs... one for each vhost.
http://www.php.net/manual/en/security.apache.php