Hightower Posted February 4, 2009 Posted February 4, 2009 I'm playing about with squid at the minute (on a Ubuntu server OS) and am very pleased with what it can do. It seems the last thing I want it to do is the one I am having most difficulty with. I want to be able to restart squid from a web page (which is served from the same server). Something like shell_exec('/etc/init.d/squid restart') This doesn't work though because of permissions. Can anybody help me achieve this please?
Hightower Posted February 4, 2009 Author Posted February 4, 2009 I could use webmin but I want this to work from a custom web script that I have designed.
powdarrmonkey Posted February 4, 2009 Posted February 4, 2009 (edited) Is this PHP? You'll have to relax some of the safety in php.ini to shell out in the first place. However, even then your shell command will run as a non-privileged user, so you won't be able to restart squid from there. You could: - run apache as root (baaad) - add apache to the root group (baaad) - [ame=http://en.wikipedia.org/wiki/Setuid]setuid[/ame] /etc/init.d/squid to run as root (baaad) I think you see the pattern. You're gambling with remote code exploits here, which is why apache isn't set up like this in the first place. But if you want to go ahead, choose one of the above (I'd go with setuid myself, it's the most minimal solution.) Edited February 4, 2009 by powdarrmonkey
Hightower Posted February 4, 2009 Author Posted February 4, 2009 The server is not open to the outside world and this script will be hidden behind an ldap authentication anyways.
Geoff Posted February 4, 2009 Posted February 4, 2009 Is this PHP? You'll have to relax some of the safety in php.ini to shell out in the first place. However, even then your shell command will run as a non-privileged user, so you won't be able to restart squid from there. You could: - run apache as root (baaad) - add apache to the root group (baaad) - setuid /etc/init.d/squid to run as root (baaad) I think you see the pattern. You're gambling with remote code exploits here, which is why apache isn't set up like this in the first place. But if you want to go ahead, choose one of the above (I'd go with setuid myself, it's the most minimal solution.) I have a slightly safer idea. If you give your php user sudo access to /etc/init.d/squid. then even if someone got in, the only think they'd be able to do is stop and start squid.
Hightower Posted February 4, 2009 Author Posted February 4, 2009 I have a slightly safer idea. If you give your php user sudo access to /etc/init.d/squid. then even if someone got in, the only think they'd be able to do is stop and start squid. How? visudo?
Geoff Posted February 4, 2009 Posted February 4, 2009 As I recall, apache runs as www-data on ubuntu. Thus if you alter /etc/sudoers like so: www-data = NOPASSWD: /etc/init.d/squid then if you 'su' to www-data, you should be able to stop/start squid. For the PHP bit, your on your own.
Hightower Posted February 4, 2009 Author Posted February 4, 2009 As I recall, apache runs as www-data on ubuntu. Thus if you alter /etc/sudoers like so: www-data = NOPASSWD: /etc/init.d/squidthen if you 'su' to www-data, you should be able to stop/start squid. For the PHP bit, your on your own. Just put exactly that line in the file and now I get >>> sudoers file: syntax error, line 16 <<< sudo: parse error in /etc/sudoers near line 16 Can't get back into file to change it back
Hightower Posted February 4, 2009 Author Posted February 4, 2009 I think you missed out the ALL? ALL = NOPASSWD:....
Geoff Posted February 4, 2009 Posted February 4, 2009 'ALL' means all users, probably not what you intended.
Hightower Posted February 4, 2009 Author Posted February 4, 2009 (edited) What I have is %www-data ALL=NOPASSWD: /etc/init.d/squid3 I have logged in as ww-data and tried restarting the squid server - apparently it went through successfully but it doesn't update my ACL's until I restart the server as root. Edited February 4, 2009 by Hightower
Geoff Posted February 4, 2009 Posted February 4, 2009 Ok, I didn't know you wanted to do that. Allow www-data to run the following: squid -k reconfigure
Hightower Posted February 4, 2009 Author Posted February 4, 2009 Just stick that in the same line as my code?
Hightower Posted February 4, 2009 Author Posted February 4, 2009 I tried this line %www-data ALL=NOPASSWD: squid3 -k reconfigure but it didn't work (broke the sudoers file again). What should I be entering?
Hightower Posted February 5, 2009 Author Posted February 5, 2009 Sorry to be pestering again, but can anybody help me with this - I'm nearly there!
Hightower Posted February 5, 2009 Author Posted February 5, 2009 I get this error when I try to run the command as www-data ERROR: Could not send signal 1 to process 4371: (1) Operation not permitted
Hightower Posted February 5, 2009 Author Posted February 5, 2009 Ok. That means its hard coded. Which means it isn't possible?
Hightower Posted February 12, 2009 Author Posted February 12, 2009 Geoff - just to keep you updated, your instructions worked a treat - it was my own n00bery that was failing me. I had the PHP as shell_exec(`squid3 -k reconfigure`); Someone over at the Ubuntu forums kindly pointed out that I needed to use sudo still shell_exec(`sudo squid3 -k reconfigure`); Thanks for all your help
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now