LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 03-14-2008, 08:18 AM   #1
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Rep: Reputation: 15
users accessing directories,files using php scripts


If a user on my server runs the following script it will show the passwd file but not the shadow file and if you change the commands to pretty much anything (ls, ls -la, rm -rf *) and it will execute the command. What do I need to change to take these permissions off the users using php or atleast off of php.

Script Example:
PHP Code:
<html>
<head>
  <title>testing what php has access to</title>
</head>
<body>
This will show /etc/passwd:<br />
<pre>
<?
system
("cat /etc/passwd");
?>
</pre>
<br />
done showing /etc/passwd
<hr /><br />
This will show /etc/shadow:<br />
<pre>
<?
system
("cat /etc/shadow");
?>
</pre>
<hr /><br />
done showing /etc/shadow.
</html>
 
Old 03-14-2008, 08:23 AM   #2
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Original Poster
Rep: Reputation: 15
also im running Redhat Enterprise server 5.1 and this issue has gone on for almost a week still waiting for Redhat to come up with a resolution as well.
 
Old 03-14-2008, 08:40 AM   #3
win32sux
Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 371Reputation: 371Reputation: 371Reputation: 371
Stick a line like this in your php.ini:
Code:
disable_functions = system
BTW, there's probably several other functions you'll also want to disable.

Last edited by win32sux; 03-14-2008 at 08:50 AM.
 
Old 03-14-2008, 09:06 AM   #4
ckob
LQ Newbie
 
Registered: Aug 2007
Posts: 22

Original Poster
Rep: Reputation: 15
thanks thats it !

redhat support is still trying to figure this one out
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Accessing files/directories using konqueror keirvt Linux - Desktop 1 05-05-2007 06:56 PM
accessing files and directories windows XP-Mandrake 10.1 Micik Linux - Networking 1 06-12-2006 12:00 PM
Calling shell scripts from PHP as other users Thin Programming 1 12-02-2005 09:17 AM
Copying linked files, replacing directories in bash scripts? ta0kira Programming 2 10-10-2004 05:46 AM
accessing files & directories - a really simple question hildog Linux - Newbie 6 10-12-2003 07:17 PM


All times are GMT -5. The time now is 12:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration