note 15023 deleted from security.apache by nlopess

From: Date: Tue, 13 Jan 2004 15:20:02 +0000
Subject: note 15023 deleted from security.apache by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-63445@lists.php.net to get a copy of this message
Note Submitter: ---- [ED note: it's not advised to enable ext/posix in an environments where security is a concern, this is also noted in the manual at php.net/posix ] Using posix_kill() function you can kill the child servers of others vhosts. (httpd) If you use safe_mode_exec_dir to restrict a path for exec programs... and use the htdocs as restricted path, the user can upload a sh binary and exec anything. The best solution is modify suexec.c and make a chroot to restricted envs... one for each vhost.

« previous php.notes (#63445) next »