LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > External Applications > PHP > ln and PHP suEXEC bug

Reply
 
Thread Tools Display Modes
  #1  
Old 04-23-2009, 06:40 AM
masood_y masood_y is offline
Senior Member
 
Join Date: Sep 2008
Posts: 121
Default ln and PHP suEXEC bug

Do you have any idea for patch PHP suEXEC with "ln" command?
Reply With Quote
  #2  
Old 04-23-2009, 07:35 AM
masood_y masood_y is offline
Senior Member
 
Join Date: Sep 2008
Posts: 121
PHP suEXEC is enale on my server.
But users can link to outside him directory with "ln" and seee other sites configuration files.
And its a big security issue.
Reply With Quote
  #3  
Old 04-23-2009, 08:14 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
Everything follow Linux/Unix file system permission, there is no magic.
Maybe, you should prevent user from execute "ln" from PHP by tighten the grip on php.ini .
Reply With Quote
  #4  
Old 04-23-2009, 01:32 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
try tuning

http://www.litespeedtech.com/docs/we...llowSymbolLink

use "If Owner Match"
Reply With Quote
  #5  
Old 04-23-2009, 01:39 PM
masood_y masood_y is offline
Senior Member
 
Join Date: Sep 2008
Posts: 121
Problem not solved by doing above tuning.
Please check your private message for see bug details.
Reply With Quote
  #6  
Old 04-23-2009, 06:29 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
Also need to set http://www.litespeedtech.com/docs/we...heckSymbolLink

to "Yes".
Reply With Quote
  #7  
Old 04-24-2009, 05:27 AM
masood_y masood_y is offline
Senior Member
 
Join Date: Sep 2008
Posts: 121
Is not resolved too.
Reply With Quote
  #8  
Old 04-24-2009, 06:08 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
There is no way to prevent the perl script from creating a symbolic link, unless you disable perl.
The best can be done is to block access to target file pointed to the symbolic link, above configuration changes does that.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:16 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.