httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Randy Terbush <ra...@zyzzyva.com>
Subject Re: setuid control WITHOUT running as root
Date Sun, 02 Jun 1996 19:17:52 GMT
>   How would you suggest doing this?
> 
>   Maybe a simple check to see if User for this VHost is defined to
>   be different from the main server id and calling the wrapper if it is?
> 
> Exactly --- check if those two integers are equal, and bypass the wrapper
> if so.  What's the fuss?
> 
> rst

No muss, no fuss. Works just dandy.

One other option here that might make some people feel even better
about this code... any installation of a wrapper program would 
default to be non-suid. Anyone who changed that would be assuming the
risks.





Mime
View raw message