Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I'm playing about with squid at the minute (on a Ubuntu server OS) and am very pleased with what it can do. It seems the last thing I want it to do is the one I am having most difficulty with.

 

I want to be able to restart squid from a web page (which is served from the same server).

 

Something like

shell_exec('/etc/init.d/squid restart')

 

This doesn't work though because of permissions. Can anybody help me achieve this please?

Posted (edited)

Is this PHP? You'll have to relax some of the safety in php.ini to shell out in the first place. However, even then your shell command will run as a non-privileged user, so you won't be able to restart squid from there.

 

You could:

 

- run apache as root (baaad)

- add apache to the root group (baaad)

- [ame=http://en.wikipedia.org/wiki/Setuid]setuid[/ame] /etc/init.d/squid to run as root (baaad)

 

I think you see the pattern. You're gambling with remote code exploits here, which is why apache isn't set up like this in the first place. But if you want to go ahead, choose one of the above (I'd go with setuid myself, it's the most minimal solution.)

Edited by powdarrmonkey
Posted
Is this PHP? You'll have to relax some of the safety in php.ini to shell out in the first place. However, even then your shell command will run as a non-privileged user, so you won't be able to restart squid from there.

 

You could:

 

- run apache as root (baaad)

- add apache to the root group (baaad)

- setuid /etc/init.d/squid to run as root (baaad)

 

I think you see the pattern. You're gambling with remote code exploits here, which is why apache isn't set up like this in the first place. But if you want to go ahead, choose one of the above (I'd go with setuid myself, it's the most minimal solution.)

 

 

I have a slightly safer idea. If you give your php user sudo access to /etc/init.d/squid. then even if someone got in, the only think they'd be able to do is stop and start squid.

Posted
I have a slightly safer idea. If you give your php user sudo access to /etc/init.d/squid. then even if someone got in, the only think they'd be able to do is stop and start squid.

 

How? visudo?

Posted

As I recall, apache runs as www-data on ubuntu. Thus if you alter /etc/sudoers like so:

 

www-data = NOPASSWD: /etc/init.d/squid

 

then if you 'su' to www-data, you should be able to stop/start squid.

 

For the PHP bit, your on your own. :)

Posted
As I recall, apache runs as www-data on ubuntu. Thus if you alter /etc/sudoers like so:

 

www-data = NOPASSWD: /etc/init.d/squid

then if you 'su' to www-data, you should be able to stop/start squid.

 

For the PHP bit, your on your own. :)

 

Just put exactly that line in the file and now I get

>>> sudoers file: syntax error, line 16 <<<
sudo: parse error in /etc/sudoers near line 16

 

Can't get back into file to change it back

Posted (edited)

What I have is


%www-data ALL=NOPASSWD: /etc/init.d/squid3

 

I have logged in as ww-data and tried restarting the squid server - apparently it went through successfully but it doesn't update my ACL's until I restart the server as root.

Edited by Hightower
Posted

Geoff - just to keep you updated, your instructions worked a treat - it was my own n00bery that was failing me.

 

I had the PHP as

shell_exec(`squid3 -k reconfigure`);

 

Someone over at the Ubuntu forums kindly pointed out that I needed to use sudo still

 

shell_exec(`sudo squid3 -k reconfigure`);

 

:doh:

 

Thanks for all your help :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...