List Info

Thread: Re: php and suexec




Re: php and suexec
country flaguser name
Canada
2007-10-24 08:43:19
Understood,
 
BUT suexec will not allow a script to be written to outside the users home directory ... right?
 
-Grant
----- Original Message -----
Sent: Monday, October 22, 2007 11:12 AM
Subject: Re: [usershttpd] php and suexec

On 10/22/07, Grant Peel <thenetnow.com>">gpeelthenetnow.com> wrote:
>;
>
> Hi Matthew,
&gt;
>
&gt; Thanks for the speedy resonse. I actually am setting suphp on a test server right now, but one of the items I was looking for was to jail users from a php standpoint similar to what suexec does for perl, i.e. can't write outside the users docroot, etc etc.
>
> If I read suphp right, it does not do that. PLEASE correct me if I am wronge!
&gt;

suexec doesn't do that either. This is no "jail", the scripts are
simply subject to regular unix file permissions granted to the
assigned user.

Joshua.

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: httpd.apache.org">users-unsubscribehttpd.apache.org
" from the digest: httpd.apache.org">users-digest-unsubscribehttpd.apache.org
For additional commands, e-mail: httpd.apache.org">users-helphttpd.apache.org


Total Control Panel Login
To: gpeelthenetnow.com Message Score: 50 High (60): Pass
From: users-return-76555-gpeel=thenetnow.comhttpd.apache.org My Spam Blocking Level: High Medium (75): Pass
    Low (90): Pass
  Block messages from this sender (blacklist)
 
This message was delivered because the content filter score did not exceed your filter level.
Re: php and suexec
user name
2007-10-24 08:45:28
On 10/24/07, Grant Peel <gpeelthenetnow.com> wrote:
>
>
> Understood,
>
> BUT suexec will not allow a script to be written to 
outside the users home directory ... right?
>

I have no idea what you mean with that sentence.

Suexec is very strict about what scripts it will LAUNCH. But
once a
script is started, it is free to do anything that is allowed
to its
user.

Joshua.

------------------------------------------------------------
---------
The official User-To-User support forum of the Apache HTTP
Server Project.
See <URL:http://htt
pd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribehttpd.apache.org
   "   from the digest: users-digest-unsubscribehttpd.apache.org
For additional commands, e-mail: users-helphttpd.apache.org


[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )