Go Back   cPanel Forums > cPanel® and WHM® (for Linux® and FreeBSD® Servers) > cPanel and WHM Discussions

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-09-2004, 04:56 PM
Registered User
 
Join Date: Feb 2004
Location: Spain
Posts: 17
Hueznar
Arrow Select or Not Select PHP SueExec Support, that's the question...

Can Anybody help me?.

I don't updated Cpanel yet because I'm not sure if I must check PHP SuExec checkbox before rebuild apache. Is it necessary to correct the bug?. The last time I compiled apache with su exec support, many php scripts failed and don't worked and .htacess php flags were ignored.

Please tell me please if compiling apache following cpanel instructions (without php su exec support) will fix the security issue or if am I obligated to select PHP Suexec

Thanks a lot for your nice help
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-09-2004, 10:33 PM
Registered User
 
Join Date: Mar 2003
Posts: 345
icanectc
You dont have to select Php SuEXEC if you dont want to. i would recommend running PHP SuEXEC for security purposes but it is not required to correct the current vuln.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-09-2004, 11:11 PM
cPanel Partner NOC
cPanel Partner NOC Badge
 
Join Date: Mar 2003
Location: Washington DC
Posts: 639
eth00 is on a distinguished road
The bug was not selecting it and as long as you run atleast current you are fine. The only version that has trouble is stable right now. I would suggest upgrading to release/current then running easyapache and adding support if you use or want it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 06-10-2004, 02:27 AM
Registered User
 
Join Date: Feb 2004
Location: Spain
Posts: 17
Hueznar
OK, Thank you very much for your help. ...I have read thousands of posts trying to know if was estrictly necessary to select php suexec support, but when I tested it last time, I discovered that many PHP Scripts were failing, and .htacess php flags were ignored having php su exec support enabled.

Appart from this, do you know more "restrictions" if I select php su exec support instead of not selecting it?

Exactly, what's the difference between using or not using it?.

I know PHP Su Exec support run scripts by the user id, but what kind of possible problems will have If I don't use it?

Thank you again for u help
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 06-12-2004, 12:42 AM
Registered User
 
Join Date: Jun 2003
Posts: 54
eurorocco
phpsuexec or not?

NOT! Forget about PHPSUEXEC!

Don't even waste your time there.

PHP is PHP. Perl is Perl. CGI is CGI. And PHP will just be user nobody and group nobody running on your computer.

I tried PHPSUEXEC and it created quite a mess. It seems PHP is okay for mundane and civilian purposes as-is.

ER

Now, suexec (for cgi-bin, like perl, is a must and is honky-dory). Suexec and PHPsuexec are different, as you must already know.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 06-12-2004, 01:28 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
I can't agree less. We have phpsuexec running on all of our servers and never had a problem with any custome - you just have to make sure that you have your file ownerrships and permissions correct.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 06-12-2004, 08:58 AM
Registered User
 
Join Date: Jun 2003
Posts: 54
eurorocco
OK! I'll give it a second look.

Having phpsuexec working well would reduce the risk of security and privacy breaches considerably.

Thanks for replying in favor of phpsuexec with such conviction. I needed someone really stating firm results to go deeper into this issue.

I'll have a second look since I really hate to see all php scripts running like user nobody and group nobody.

ER
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 06-12-2004, 09:12 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
Having used suexec for so many years, I think it's only sensible security to run phpsuexec these days. I understand that phpsuexec was flawed at its introduction.

The number of threads on here with people asking about all the spam emails from nobody has convinced me that any pain in running it outweighs the risks of not.

There is also an alternative that some use called suphp:
http://www.suphp.org/Home.html

Never needed to try it myself.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:30 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc