Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

To PHPsuexec or not

 
   Web Hosting and Web Master Forums (Home) -> Webmaster RSS
Next:  Proboards? Anyone Know What Happened?  
Author Message
webfive

External


Since: Feb 23, 2004
Posts: 6



(Msg. 1) Posted: Sat Mar 27, 2004 1:42 pm
Post subject: To PHPsuexec or not
Archived from groups: alt>www>webmaster (more info?)

Can any knowledgeable Webmaster comment please. I have one virtual account
where suexec has been suspended (without any warning) because it apparently
caused so much hassle ?
Writing directory folders - say for graphics temp storage - without suexec
creates the entry obviously as nobody where Apache and chmod permissions
have to be 777 leaving that area open to any other script writing to it.
Suexec obviously uses 755 UID/GUI and nobody's are excluded.
Has anyone experienced the danger of this non suexec loophole. Or for that
matter have opinions on how vulnerable an application is with write
permissions enabled.
Thanks Tony

--
Inkylink JetTec UK Quality - Wot others wanna-be
Epson C64/ C84 Lighfast (30% more free) pigmented inks.
Canon BCI-3 i560 i750 BCI-6 i865 S-820 / S-900 series.
Specialist ink refill kits... http://www.inkylink.co.uk
remove pants for personal mail

 >> Stay informed about: To PHPsuexec or not 
Back to top
Login to vote
alan

External


Since: Jul 01, 2003
Posts: 56



(Msg. 2) Posted: Sat Mar 27, 2004 2:41 pm
Post subject: Re: To PHPsuexec or not [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Carved in mystic runes upon the very living rock, the last words of
Tony1that matters of alt.www.webmaster make plain:

 > Writing directory folders - say for graphics temp storage - without
 > suexec creates the entry obviously as nobody where Apache and chmod
 > permissions have to be 777 leaving that area open to any other script
 > writing to it. Suexec obviously uses 755 UID/GUI and nobody's are
 > excluded. Has anyone experienced the danger of this non suexec
 > loophole. Or for that matter have opinions on how vulnerable an
 > application is with write permissions enabled.

I don't know about the pros and cons of using suexec specifically, but
having scripts run under your user ID, either with suexec or a wrapper,
is a security must, to avoid having to leave files open.

--
Alan Little
Phorm PHP Form Processor
<a style='text-decoration: underline;' href="http://www.phorm.com/" target="_blank">http://www.phorm.com/</a><!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: To PHPsuexec or not 
Back to top
Login to vote
Display posts from previous:   
   Web Hosting and Web Master Forums (Home) -> Webmaster All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]