ln and PHP suEXEC bug

masood_y

Well-Known Member
#2
PHP suEXEC is enale on my server.
But users can link to outside him directory with "ln" and seee other sites configuration files.
And its a big security issue.
 

mistwang

LiteSpeed Staff
#3
Everything follow Linux/Unix file system permission, there is no magic.
Maybe, you should prevent user from execute "ln" from PHP by tighten the grip on php.ini .
 

mistwang

LiteSpeed Staff
#8
There is no way to prevent the perl script from creating a symbolic link, unless you disable perl.
The best can be done is to block access to target file pointed to the symbolic link, above configuration changes does that.
 
Top