[Apache] Mensen insluiten in hun "homedir"?

Pagina: 1
Acties:

  • Alex)
  • Registratie: Juni 2003
  • Laatst online: 06-07 14:10
Hoi,
ik heb al wel gezocht op Google, maar omdat ik niet precies weet hoe ik het moet omschrijven, leg ik het hier maar uit:
Ik wil binnenkort misschien een cursus PHP gaan geven. Ik wil de cursisten zelf voorzien van webruimte, ruimte zat beschikbaar :Y)
Nu heb ik wel een probleem.
Ik wil alle cursisten onderbrengen in één subdomein, http://cursus.alex-web.nl.
De cursisten krijgen een map van 10 MB, /cursistnaam.
Dan krijg je dus bijvoorbeeld
http://cursus.alex-web.nl/piet
http://cursus.alex-web.nl/kees
http://cursus.alex-web.nl/henk
Ik kan geen users aanmaken zoals in Apache (tenminste niet via het website control panel WSCP, het is custom-made).
Ik kan wel FTP-gebruikers toegang geven tot één map, dus /cursus/piet voor de gebruiker piet.
Nu wil ik voorkomen dat de cursisten via een PHP-script buiten hun 'homedirectory' kunnen komen. (Dus dat een script http://cursus.alex-web.nl/piet/kijkinmapjekees.php in /cursus/kees kan komen.)
Dit lijkt me mogelijk met .htaccess, maar hoe moet ik dat dan doen? Of is dit helemaal niet mogelijk?

We are shaping the future


  • Spider.007
  • Registratie: December 2000
  • Niet online

Spider.007

* Tetragrammaton

Dit?
open_basedir

Limit the files that can be opened by PHP to the specified directory-tree, including the file itself. This directive is NOT affected by whether Safe Mode is turned On or Off.

When a script tries to open a file with, for example, fopen() or gzopen(), the location of the file is checked. When the file is outside the specified directory-tree, PHP will refuse to open it. All symbolic links are resolved, so it's not possible to avoid this restriction with a symlink.

The special value . indicates that the working directory of the script will be used as the base-directory. This is, however, a little dangerous as the working directory of the script can easily be changed with chdir().

In httpd.conf, open_basedir can be turned off (e.g. for some virtual hosts) the same way as any other configuration directive with "php_admin_value open_basedir none".

Under Windows, separate the directories with a semicolon. On all other systems, separate the directories with a colon. As an Apache module, open_basedir paths from parent directories are now automatically inherited.

The restriction specified with open_basedir is actually a prefix, not a directory name. This means that "open_basedir = /dir/incl" also allows access to "/dir/include" and "/dir/incls" if they exist. When you want to restrict access to only the specified directory, end with a slash. For example: "open_basedir = /dir/incl/"

Note: Support for multiple directories was added in 3.0.7.

The default is to allow all files to be opened.

---
Prozium - The great nepenthe. Opiate of our masses. Glue of our great society. Salve and salvation, it has delivered us from pathos, from sorrow, the deepest chasms of melancholy and hate


  • Alex)
  • Registratie: Juni 2003
  • Laatst online: 06-07 14:10
En hoe zet ik dit dan in een .htaccess?
Moet ik dan in iedere map een .htaccess zetten of in de root?
code:
1
php_flag open_basedir on
ofzo?

We are shaping the future


  • Spider.007
  • Registratie: December 2000
  • Niet online

Spider.007

* Tetragrammaton

In httpd.conf, open_basedir can be turned off (e.g. for some virtual hosts) the same way as any other configuration directive with "php_admin_value open_basedir none".
en hem op 'on' zetten zal niet werken; je moet er een directory inzetten zoals ook gedocumenteerd. Zet dus in de homedirectory van iedere user een .htaccess (liefst 1 niveau hoger zodat ze er niet bijkunnen) met de locatie van hun homedriver erin als open_basedir :)

---
Prozium - The great nepenthe. Opiate of our masses. Glue of our great society. Salve and salvation, it has delivered us from pathos, from sorrow, the deepest chasms of melancholy and hate


  • Alex)
  • Registratie: Juni 2003
  • Laatst online: 06-07 14:10
Dat is nou net het punt. Ik kan maximaal 1 subniveau opgeven, dus ik kan niet instellen dat de gebruiker rechten heeft tot /cursus/piet/htdocs. Kan ik misschien een file wegzetten en 'm zo chmodden dat ze er niets mee kunnen? Ik heb SSH-toegang.

We are shaping the future


  • Spider.007
  • Registratie: December 2000
  • Niet online

Spider.007

* Tetragrammaton

Als de webserver niet onder dezelfde account draait als de users dan kun je natuurlijk de users de rechten op de .htaccess gewoon ontnemen en zorgen dat de webserver er wel bijkan?

---
Prozium - The great nepenthe. Opiate of our masses. Glue of our great society. Salve and salvation, it has delivered us from pathos, from sorrow, the deepest chasms of melancholy and hate


  • Alex)
  • Registratie: Juni 2003
  • Laatst online: 06-07 14:10
Dat is ook een probleem. Eergisteren hebben ze dat systeem omgegooid, zodat klanten ook via de FTP-toegang bestanden kunnen wissen, die door PHP of Perl o.i.d. zijn gemaakt...
Ach, als ik dingen uitleg a.d.h.v. CuteFTP, ziet men die .htaccess niet eens. En ik maak wel wat backups, mocht iemand 'm wissen, dan kan ik 'm terugzetten.

We are shaping the future

Pagina: 1