Re: [PHP4BETA] UID PHP running on????
| From: | Rasmus Lerdorf | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: [PHP4BETA] UID PHP running on???? | ||
| References: | 1 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-6804@lists.php.net to get a copy of this message | ||
> I was a little bit playing with PHP4 (compiled into Apache 1.3.9) when
> I discovered the following...
>
> PHP file source:
> ----------------
>
> if ( copy('/home/www/html/local/index.html', '/tmp/php.test1') ) {
> print("File copy succeeded!<br>\n");
> }
> else {
> print("File copy NOT succeeded.<br>\n");
> }
>
> if ( copy('/etc/passwd', '/tmp/php.test2') ) {
> print("File copy succeeded!<br>\n");
> }
> else {
> print("File copy NOT succeeded.<br>\n");
> }
>
>
> Result in browser:
> ------------------
>
> File copy succeeded!
>
> Warning: SAFE MODE Restriction in effect.
> The script whose uid is 406 is not allowed to access /etc/passwd
> owned by uid 0 in /home/www/html/local/php/file_io_test.php on line 13
> File copy NOT succeeded.
>
> --
>
> Weird thing however is that my Apache server is running as nobody.www.
> Why is the script saying that it is running as uid 406???
>
> #> ll /tmp/php*
> -rwxr-xr-x 1 nobody www 990 Nov 23 23:44 /tmp/php.test1
>
> This proves that it _is_ running nobody.www.
>
> Who can explain this? What is happening?
That's how safe mode works. It checks to see who owns the script that is
currently executing and then the various file commands in that script can
only be applied to files or dirs owned by the same user. Your script
isn't actually running as that user.
> And why is the destination file executable? The original wasn't!
umask
-Rasmus