Re: Maby a litle OT but: apache+sh CGI script

From: Zergin (idioten@poczta.onet.pl)
Date: 05/22/02


From: "Zergin" <idioten@poczta.onet.pl>
Date: Wed, 22 May 2002 14:21:16 +0200


>
> It *CAN*, but you need to select appropriate options for it compilation
time
> for the suexec module. Very few people do, it's just too damned dangerous
to
> allow.
>
>

Didn't know that. But any way I would'n do so. I've got it working this way
that the http user is added to sudoers and may execute (w/o pass.) only
thouse commands that it realy needs for the script. And in the script every
command needing root priv. is executed with sudo before. Then the script is
executed with http priv. and only some commands run as root.

What do you think of that? Is this really killing my sys. security? Guess
it's safer then giving apache full root priv.

TIA,
M.



Relevant Pages

  • Re: head, recursively through file tree?
    ... What's the problem with running a shell or perl inline script ... | child-process to execute the user's commands. ... the shell forks a process for every command it runs unless ...
    (comp.unix.shell)
  • Re: Maby a litle OT but: apache+sh CGI script
    ... > thouse commands that it realy needs for the script. ... > it's safer then giving apache full root priv. ... What are you trying to execute via CGI? ...
    (comp.os.linux.security)
  • Re: Maby a litle OT but: apache+sh CGI script
    ... > thouse commands that it realy needs for the script. ... > it's safer then giving apache full root priv. ... What are you trying to execute via CGI? ...
    (comp.os.linux.security)
  • Re: Maby a litle OT but: apache+sh CGI script
    ... that the http user is added to sudoers and may execute only ... thouse commands that it realy needs for the script. ... it's safer then giving apache full root priv. ...
    (comp.os.linux.security)
  • Re: How to copy scripts to the Terminal
    ... Use 'sh' to execute the commands in the script (if the USB drive is ... > I have been key entering and save it on a removeable device (USB Flash ...
    (alt.linux)