Mombu the Php Forum

Go Back   Mombu the Php Forum > Php > chrooted php5-cgi in a non chrooted apache
User Name
Password
REGISTER NOW! Mark Forums Read




Reply Bookmark and Share
1 26th October 15:17
joerg
External User
 
Posts: 1
Default chrooted php5-cgi in a non chrooted apache



Hi,

actually I try to make my webserver-installation more secure. I've
something in mind, but don't know if it is possible and if so, how to do
it ;-)

Actually I have the following config:

Directory-Structure:

/var/www
domain1
conf
cgi-bin
web
htdocs
logs
domain2


I've installed mod_fastcgi in apache and uses suexec.
In each /var/www/domainx/cgi-bin I have a php-fcgi-starter-file, which
starts /usr/bin/php5-cgi.

Actually I see the following problem: I can run each "domain" under a
different user, but the developer within each "domain" can program
php-code to at least VIEW a lot of other things outside the
domain-directory.

Now I thought about the following:
If I can create a chroot-jail within /var/www/domainx/web and let
php5-cgi be executed within this chroot-jail, the developers would only
see there own directory structure like
var/www/domain1/web
etc
bin
usr
home

What I've get so far is, that I've created a chroot jail within the
web-directory. I can chroot to there and execute php (I used "jailer",
for this).

But I don't get it to work that mod_fastcgi starts the chroot-jail.

I googled a lot, but only found howtos and tutorials how to put the
complete apache into a jail, but this is not what I want. Each domain
have to be in its own jail.

Can someone help me / point me in the right direction?


Thanks in advance

Joerg Schoppet
  Reply With Quote


 


2 26th October 15:22
jochem
External User
 
Posts: 1
Default chrooted php5-cgi in a non chrooted apache



hi Joerg,

not a solution but the open_basedir ini setting on a per Vhost
setting may offer a [partial] work around
  Reply With Quote
3 26th October 15:26
joerg
External User
 
Posts: 1
Default chrooted php5-cgi in a non chrooted apache


Hi Jochem,


Joerg
Jochem Maas wrote:
  Reply With Quote
4 29th October 18:11
joerg
External User
 
Posts: 1
Default chrooted php5-cgi in a non chrooted apache


Hi,

no more tips for this problem?


Joerg Schoppet
  Reply With Quote
5 29th October 18:11
frank.arensmeier
External User
 
Posts: 1
Default chrooted php5-cgi in a non chrooted apache


Maybe the Apache mailing list is a better place to ask.

http://httpd.apache.org/userslist.html

//frank

16 nov 2007 kl. 12.20 skrev Joerg Schoppet:
  Reply With Quote
Reply


Thread Tools
Display Modes


Some other forums that might be of your interest : Php 5 forum, Apache forum, Iis forum, Functions forum, Classes forum, Librarys forum, Bugs forum, Postgres forum, Mysql forum, Paradox forum, Ms sql forum, Configurations forum, Php.ini forum, Problems forum, Scripting forum, Css forum, General forums, Off-topic talk, Links, Extra forums, Php


Copyright © 2006 SmartyDevil.com - Dies Mies Jeschet Boenedoesef Douvema Enitemaus -
666