Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-10-06 Thread Stefan Fritsch
On Thursday 02 October 2008, Alexander Prinsier wrote: > > Apart from that, allowing scripts owned by root to be executed as > > any user would certainly create (local) security issues. Using a > > dedicated user might be possible, though. > > Why would running a root-owned script as a local user c

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-10-03 Thread J.M.Roth
Ondřej Surý wrote: >> So the actual item for the wishlist is to be able to specify a user (or more >> than one) that are considered trusted. Suexec will then allow files >> owned by either the target user, or by a trusted user, to be executed. > > Use chattr +i > > Ondrej. That much we had alr

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-10-03 Thread Ondřej Surý
> So the actual item for the wishlist is to be able to specify a user (or more > than one) that are considered trusted. Suexec will then allow files > owned by either the target user, or by a trusted user, to be executed. Use chattr +i Ondrej. -- Ondřej Surý <[EMAIL PROTECTED]>

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-10-02 Thread Alexander Prinsier
Stefan Fritsch wrote: >> So the actual item for the wishlist is to be able to specify a user >> (or more than one) that are considered trusted. Suexec will then >> allow files owned by either the target user, or by a trusted user, >> to be executed. > > First of all, have you looked at > > suphp

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-09-22 Thread Stefan Fritsch
Hi, On Wednesday 17 September 2008, Alexander Prinsier wrote: > I'm using apache2 together with fastcgi, suexec and php. To > configure php I'm using a wrapper script to set PHPRC, which then > exec's php itself. > > I don't want users to set their own PHPRC, so they could modify the > php.ini for

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-09-16 Thread Alexander Prinsier
Package: apache2-suexec-custom Severity: wishlist I'm using apache2 together with fastcgi, suexec and php. To configure php I'm using a wrapper script to set PHPRC, which then exec's php itself. I don't want users to set their own PHPRC, so they could modify the php.ini for their site. This mea