Return-Path: Delivered-To: apmail-httpd-users-archive@httpd.apache.org Received: (qmail 49961 invoked by uid 500); 2 Apr 2003 18:04:26 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: list-post: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 49900 invoked from network); 2 Apr 2003 18:04:25 -0000 Received: from venus.commerce.ubc.ca (137.82.154.16) by daedalus.apache.org with SMTP; 2 Apr 2003 18:04:25 -0000 Received: from exchange.commerce.ubc.ca (exchange.commerce.ubc.ca [137.82.66.44]) by venus.commerce.ubc.ca (8.9.3/8.9.3) with ESMTP id KAA14365 for ; Wed, 2 Apr 2003 10:04:29 -0800 Received: from res206.pwias.ubc.ca ([137.82.77.51]) by exchange.commerce.ubc.ca with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2656.59) id 2DLPAJXN; Wed, 2 Apr 2003 10:05:16 -0800 Date: Wed, 2 Apr 2003 13:04:26 -0500 (Est) From: Joshua Slive To: users@httpd.apache.org In-Reply-To: <002701c2f919$635c57d0$daf09d18@alpha> Message-ID: References: <002701c2f919$635c57d0$daf09d18@alpha> X-X-Sender: slive@exchange.commerce.ubc.ca MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N Subject: Re: [users@httpd] safe environment list On Wed, 2 Apr 2003, Dmitri wrote: > However, the question is, how to make suEXEC _NOT_ clean up certain > variables? I looked everywhere and couldn't find any references to > configuring the list, except the above fragment. > So i had to edit suexec.c, which doesn't seem like a good solution. There > don't seem to be any such configure options or anything at all. Is it just > me or is the list not designed to be configured? Editting suexec.c is the only solution. A basic part of the security model of suexec is that it is NOT run-time configurable. Violating this rule could allow users to exploit suexec. By forcing all configuration to compiled into the binary, suexec assures that an administrator can know exactly what happens when he/she grants suid permissions to that binary. Joshua. --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See for more info. To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org " from the digest: users-digest-unsubscribe@httpd.apache.org For additional commands, e-mail: users-help@httpd.apache.org