nginx + php fpm security issue?

General Tech Bugs & Fixes 2 years ago

0 2 0 0 0 tuteeHUB earn credit +10 pts

5 Star Rating 1 Rating

Posted on 16 Aug 2022, this text provides information on Bugs & Fixes related to General Tech. Please note that while accuracy is prioritized, the data presented might not be entirely correct or up-to-date. This information is offered for general knowledge and informational purposes only, and should not be considered as a substitute for professional advice.

Take Quiz To Earn Credits!

Turn Your Knowledge into Earnings.

tuteehub_quiz

Answers (2)

Post Answer
profilepic.png
manpreet Tuteehub forum best answer Best Answer 2 years ago

I am new user of nginx + php-pfm, but I am a little bit confused about security.

For example I am running a few pools with different uid/gid as TCP sockets. So theoritically it is possible that any local shell user can connect to 127.0.0.1 9000 OR 9001 or any other FPM port and send php code to execute with different uids? How to avoid that? (file sockets is not an option)

profilepic.png
manpreet 2 years ago

You can't send code to be executed, only path to file to execute. And it has to be readable by the user your FPM pool runs as. So this bad user would have to be able to create a file with permissions to be read by FPM.


0 views   0 shares

No matter what stage you're at in your education or career, TuteeHub will help you reach the next level that you're aiming for. Simply,Choose a subject/topic and get started in self-paced practice sessions to improve your knowledge and scores.