LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > External Applications > Apache Migration/Compatibility > [solved] open_basedir tweak via cpanel not supported

Reply
 
Thread Tools Display Modes
  #1  
Old 05-07-2007, 03:05 AM
aww aww is offline
Senior Member
 
Join Date: May 2007
Posts: 237
Default [solved] open_basedir tweak via cpanel not supported

Cpanel's "tweak security" offers a menu option to turn on open_basedir on a per user basis.

Litespeed doesn't seem to obey cpanel (not surprisingly as cpanel is probably writing php.ini in another directory)

How do I enable this manually?
Any issues to consider under LiteSpeed vs apache?

Quote:
Tweak php open_basedir Security

php open_basedir Protection

Php's open_basedir protection prevents users from opening files outside of their home directory with php.

Last edited by NiteWave; 05-20-2011 at 08:02 PM..
Reply With Quote
  #2  
Old 05-07-2007, 04:29 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
cPanel override "open_basedir" for each virtual host in httpd.conf, it is honored by LiteSpeed, Please check it via a phpinfo page.
Reply With Quote
  #3  
Old 05-07-2007, 10:38 AM
aww aww is offline
Senior Member
 
Join Date: May 2007
Posts: 237
Well you are right, it's in phpinfo

However if I remember correctly under apache+php if you try something as simple as this, it should fail as it's trying to read a path outside the owner's own folder

echo file_get_contents('/proc/loadavg');

lsws+php+open_basedir is allowing it to happen without error
Reply With Quote
  #4  
Old 05-07-2007, 10:43 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
As I knew, it is a bug in PHP 4.4.6, but PHP team won't fix it, you can check PHP's bug reports.
Reply With Quote
  #5  
Old 05-07-2007, 10:44 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
Same thing will happen with Apache mod_php.
Reply With Quote
  #6  
Old 05-07-2007, 10:56 AM
aww aww is offline
Senior Member
 
Join Date: May 2007
Posts: 237
Ah my apologies then.
I could have sworn it failed under my apache+php which was 4.4.6

Later tonight when traffic is slower I will switch back to apache temporarily just to double check (and see what php version I am actually running under that)

Was I at least right about the /~username issue?

Last edited by aww; 05-07-2007 at 11:04 AM..
Reply With Quote
  #7  
Old 05-07-2007, 03:22 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
There is a thread in webhostingtalk about PHP 4.4.6 + Apache, http://www.webhostingtalk.com/showthread.php?t=601125

We are investigating the user dir issue.
Reply With Quote
  #8  
Old 05-07-2007, 09:38 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
PHP 4.4.7 has been released, it might be fixed.
Reply With Quote
  #9  
Old 05-07-2007, 10:29 PM
aww aww is offline
Senior Member
 
Join Date: May 2007
Posts: 237
Please forgive my ignorance, for a php upgrade do we upgrade though your installer? So basically we have to wait until you make a package 4.4.7 ? (not rushing you, just trying to understand the process)
Reply With Quote
  #10  
Old 05-08-2007, 08:24 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
You'd better building your own PHP binary, just follow tutorial in our wiki.
It is the only way to get it up-to-date as early as you can.
Make sure to uninstall eAccelerator before upgrade PHP to another version, then install it again after the upgrade.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 12:43 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.