note 15023 deleted from security.apache by nlopess
| From: | nlopess@php.net | Date: | Tue, 13 Jan 2004 15:20:02 +0000 |
| Subject: | note 15023 deleted from security.apache by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-63445@lists.php.net to get a copy of this message | ||
Note Submitter:
----
[ED note: it's not advised to enable ext/posix in an environments where security is a concern,
this is also noted in the manual at php.net/posix ]
Using posix_kill() function you can kill the child servers of others vhosts. (httpd)
If you use safe_mode_exec_dir to restrict a path for exec programs... and use the htdocs as
restricted path, the user can upload a sh binary and exec anything.
The best solution is modify suexec.c and make a chroot to restricted envs... one for each vhost.