perl-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Stas Bekman <s...@stason.org>
Subject security (fwd)
Date Thu, 01 Mar 2001 01:48:34 GMT
Doug, do you plan to answer these concerns (see below) in 2.0? This kind
of question pops up quite often and it's a legitimate one, to allow ISPs
using mod_perl mainstream.

So will it be possible to make pools of interpreters with different
owners, running under different UID/GID? I can think of MPM model where
there are different processes, each potentially owned by a different owner
and having a pool of threads inside of each.

---------- Forwarded message ----------
Date: Wed, 28 Feb 2001 21:48:00 +0000
From: Gustavo Vieira Goncalves Coelho Rios <gustavo@ifour.com.br>
To: modperl@apache.org
Subject: security

Hi folks!

I have a FreeBSD server configured as a http server, running apache.
This installation includes mod_perl+EmbPerl, mod_php4 mod_cgi and
mod_fastcgi. Some of my users will be using mysql for database. The
problem is that this scenario requires sensitive information inside
file. This means no problem when these users write their dymanic pages
inside a compiled program. I can chmod a-rw and nobody will be able to
take away user/password from a compiled program. The problem happens
when write their php or embperl pages!

the key user\password are kept inside this file, so anyone can uses an
editor to retrieve the user mysql account. I resolve this problem
running php on secure mode and chgrping the php file the same user as
the http process and removing other flags file access (g-rwx). So nobody
besides the owner of the file (or the http process) will be able to read
it.

since php have some security facilities, like: if the file owner id !=
the file the script is trying to open => fails.
My problem is with perl: how to solve such a problem in a perl
environment?
Does mod perl allows any kind of security, to prevent ones writing
script to read others files?


PS: All cgi runs through suexec, so even cgi are not able to run the
script, ok?


Mime
View raw message