Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > H-Sphere Pre-Sales
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

H-Sphere Pre-Sales Post your questions about H-Sphere plans here.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 09-09-2003, 12:21 AM
Light Speed's Avatar
Light Speed Light Speed is offline
Scoundrel
Vortech Inc. Customer
 
Location: Portland
Question for Bladesnitz re: PHP

My current host just switched PHP from running as Apache module to running as CGI and they enabled phpsuexec.

Are there and plans for Matrix to do the same (please say no)?
Reply With Quote
  #2  
Old 09-09-2003, 12:48 AM
Bladesnitz
Guest
 
No, running php as CGI would be a horrible thing to do.
Reply With Quote
  #3  
Old 09-09-2003, 01:11 AM
alexc
Guest
 
Kind of beats the point, doesn't it?
Reply With Quote
  #4  
Old 09-09-2003, 03:57 AM
Light Speed's Avatar
Light Speed Light Speed is offline
Scoundrel
Vortech Inc. Customer
 
Location: Portland
Thanks

Yes it is a pain in the A$$ and that's why I am moving here today

Thanks Bladenitz!
Reply With Quote
  #5  
Old 09-09-2003, 06:21 AM
Garreg's Avatar
Garreg Garreg is offline
Resident Optimist
Vortech Inc. Customer
 
Location: UK - Mon to Fri. Mars - all Weekend
Duh !
I expect you won't be the only one leaving them
__________________
Regards to all
Reply With Quote
  #6  
Old 09-09-2003, 08:42 AM
bootNumlock's Avatar
bootNumlock bootNumlock is offline
Brangwyn fan club member
Vortech Inc. Customer
 
Location: chicago
for someone that is by no stretch an expert in php, apache or cgi -- why would a host choose to make such a move?
__________________
boot numlock
Reply With Quote
  #7  
Old 09-09-2003, 01:18 PM
Light Speed's Avatar
Light Speed Light Speed is offline
Scoundrel
Vortech Inc. Customer
 
Location: Portland
They say they did it for security.

PHP as module writes ownership as nobody so in theory users/account holders could gain access to other account holders data. They wanted to run phpsuexec which utilizes php as cgi so new things written have ownership of user. It also limits your permissions to a more restictive level for php files.

Not sure if my explanation is exactly right but you get the idea.

Seems like a good sys admin should have a better way to make a secure environment.
Reply With Quote
  #8  
Old 09-09-2003, 03:51 PM
alexc
Guest
 
Of course PHP does not have a security record that I'd call stellar. I presume that that's their prime cause of concern. They're also pretty damn fast on the draw when it comes to patching bugs.

Since you'll find PHP running as user nobody (or www or httpd or whatever apache runs as), the potential for abuse concerns access control and race conditions rather than privilege escalation. The threat to system security is low. User data are more vulnerable than the system itself if an exploitable hole is found in PHP.

We reckon that our userbase accepts that risk and trusts us to be on the ball and stay current. If you're going to run CGI, you might as well use Perl. PHP was designed to bypass the mess that CGI can sometimes be, and suexec of any flavour carries risks of its own and is an evil we prefer to do without as much as possible.
Reply With Quote
  #9  
Old 09-09-2003, 04:01 PM
Light Speed's Avatar
Light Speed Light Speed is offline
Scoundrel
Vortech Inc. Customer
 
Location: Portland
I agree.

That's why I signed up here today

If the userbase consists of business oriented people then the risk is greatly reduced. If some idiot comes in ban him and inform other hosting providers of this person.
Reply With Quote
  #10  
Old 09-09-2003, 04:06 PM
Bladesnitz
Guest
 
In the near future, we may be able to support Apache2, which lets HTTPD threads run under different user/groups. Thats kinda like suexec for cgi, except its for the basic httpd process - without a huge performance hit (in theory).

Its a really neat feature. Then only you and your httpd process have access to your files... as it stands now, I think you have to 777 dirs if want php to be able to save there... Not quite sure
Reply With Quote
  #11  
Old 09-09-2003, 06:52 PM
landiserve
Guest
 
Apache2 is rather nice, but will hsphere suppor tthe change anytime soon, as I remember the config files are a bit different (at least when I used the early apache2 versions they differed a bit)
Reply With Quote
  #12  
Old 09-09-2003, 08:02 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Would that in anyway fix the issue that exists today with disk allocations being wrong ? right now theres seems to be a bit of an issue with files uploaded to the server via php scripts etc becuase if done this way the file is then owned by HTTPD, H-Sphere calculates disk usage based on owner so folks are able to exceed their disk allocations basically by just uploading files via script rather than FTP.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:03 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.56454 seconds with 15 queries
[Output: 82.53 Kb. compressed to 75.41 Kb. by saving 7.12 Kb. (8.63%)]