Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

suEXEC starts but doesn't protect

Status
Not open for further replies.

ourside

MIS
Jun 23, 2000
1
US
I compiled apache_1.3.12 and compiled suEXEC, when I start Apache it says:<br>[notice] suEXEC mechanism enabled (wrapper: /usr/local/apache/bin/suexec) <br>in the error file, so I know that is is stating, but suEXEC seems to be ignoring ALL the rules it should be protecting.&nbsp;&nbsp;In Apaches docs it says that it will not run files world writtable, or files owned by root, or files in a world writtable directory.&nbsp;&nbsp;Well I wanted to test it and make sure that it was working right, and it will run all scripts in under every circumstance.&nbsp;&nbsp;Any idea what is wrong?&nbsp;&nbsp;I compiled it with these options:<br>--enable-suexec <br>--suexec-caller=same_as_my_apache_user<br>--suexec-userdir=public_html<br>--suexec-docroot=/same_as_apache_doc_root<br>--suexec-logfile=/my_log_path/suexec-log <br>--suexec-uidmin=500 <br>--suexec-gidmin=500<br>--suexec-safepath=/usr/bin:/usr/local/bin<br><br>I have only received one error in my suexec-log file on all of the files that I run illegaly, that error was:<br>alert: too few arguments<br>Again, showing that it is running, but not protecting.<br><br>I am running virtual domains on this box, the path to the virtual domain directories is /same_as_apache_doc_root/virtual_domain<br>I have put:<br>user otherUser<br>group otherUser<br>To specify a different user/group then the one that apache is running as.&nbsp;&nbsp;<br><br>Any ideas would be very helpful.<br><br>Thanks,
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top