7

I have a Debian Lenny web server. It is running apache2 with libapache2-mod-suphp. Unfortunately, suphp makes impossible to use phpmyadmin, as phpmyadmin is installed in /usr/share/phpmyadmin and owned by root, and suphp disables it's engine in this direcory:

$ cat /etc/apache2/mods-enabled/suphp.conf 
<IfModule mod_suphp.c>
    AddType application/x-httpd-php .php .php3 .php4 .php5 .phtml
    suPHP_AddHandler application/x-httpd-php
    <Directory />
        suPHP_Engine on
    </Directory>

    # By default, disable suPHP for debian packaged web applications as files
    # are owned by root and cannot be executed by suPHP because of min_uid.
    <Directory /usr/share>
        suPHP_Engine off
    </Directory>
</IfModule>

Is there a possibility to enable system phpmyadmin (may be through standard libapache2-mod-php5) while using suphp? How?

thor
  • 648
  • 1
  • 7
  • 18

3 Answers3

11

In /etc/apache2/mods-available/suphp.conf following two lines:

AddType application/x-httpd-php .php .php3 .php4 .php5 .phtml
suPHP_AddHandler application/x-httpd-php

should be changed to:

AddType application/x-httpd-suphp .php .php3 .php4 .php5 .phtml
suPHP_AddHandler application/x-httpd-suphp

Then, in /etc/suphp/suphp.conf line

application/x-httpd-php=php:/usr/bin/php-cgi

should be changed to:

application/x-httpd-suphp=php:/usr/bin/php-cgi

Then, contents of /etc/apache2/mods-available/php5.conf should be changed from:

<IfModule mod_php5.c>
  AddType application/x-httpd-php .php .phtml .php3
  AddType application/x-httpd-php-source .phps
</IfModule>

to:

<Directory /usr/share>
    <IfModule mod_php5.c>
      AddType application/x-httpd-php .php .phtml .php3
      AddType application/x-httpd-php-source .phps
    </IfModule>
</Directory>

This way, all php scripts get assigned x-httpd-suphp type which is handled by suphp. As suphp is disabled for files in /usr/share, in php5.conf for this directory php scripts get type of x-httpd-php and are handled by mod_php5. This way, you retain suphp for all other scripts except for system-installed ones in /usr/share.

thor
  • 648
  • 1
  • 7
  • 18
  • Good answer, and better than some of the more convoluted solutions that popup on Google, involving running phpmyadmin in a vhost, etc. Thanks thor. – zlovelady Apr 01 '12 at 05:41
  • 1
    The author of suPHP states that running mod_php and suphp at the same time is too dangerous. It allows a remote attacker to modify a targeted user's files. If you are sure it is impossible suPHP get invoked in /usr/share adn mod_php cannot be invoked outside /usr/share, then I guess this configuration is safe. Otherwise, you have created a security hole in your server. Reference: http://seclists.org/bugtraq/2004/Aug/att-320/suphp-advisory.txt – MV. Jun 17 '12 at 07:41
  • @MV. How did you get it running? I'm on 12.04, added /usr/share/phpmyadmin to docroot in /etc/suphp/suphp.conf and switched the engine on in the apache config. Getting lost in what permissions to set the files, and a possible ubuntu bug with it not reading the config.inc.php so i can set the blowfish secret (yep, i found the one in /var/lib after googling in circles for hours). Do you have a blog post or some tips somewhere on the web? cheers! – Steve Aug 19 '12 at 10:14
3

The configuration files have changed since the time of the original answer.

These files no longer need to be changed:

/etc/apache2/mods-available/suphp.conf
/etc/suphp/suphp.conf

This file:

/etc/apache2/mods-available/php5.conf 

only needs the <Directory /usr/share> wrapper around the current file.

e.g.:

<Directory /usr/share>
  {original php5.conf contents}
</Directory>

== Current copies of the Files for ==

NAME="Ubuntu"
VERSION="14.04.5 LTS, Trusty Tahr"
Linux anon 4.2.0-27-generic #32~14.04.1-Ubuntu SMP Fri Jan 22 15:32:26 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux

root@local [~]# cat /etc/apache2/mods-available/suphp.conf

<IfModule mod_suphp.c>
    <FilesMatch "\.ph(p3?|tml)$">
        SetHandler application/x-httpd-suphp
    </FilesMatch>
        suPHP_AddHandler application/x-httpd-suphp

    <Directory />
        suPHP_Engine on
    </Directory>

    # By default, disable suPHP for debian packaged web applications as files
    # are owned by root and cannot be executed by suPHP because of min_uid.
    <Directory /usr/share>
        suPHP_Engine off
    </Directory>

# # Use a specific php config file (a dir which contains a php.ini file)
#       suPHP_ConfigPath /etc/php5/cgi/suphp/
        suPHP_ConfigPath /etc/php5/apache2
# # Tells mod_suphp NOT to handle requests with the type <mime-type>.
#       suPHP_RemoveHandler <mime-type>
</IfModule>

root@local [~]# cat /etc/suphp/suphp.conf

[global]
;Path to logfile
logfile=/var/log/suphp/suphp.log

;Loglevel
loglevel=info

;User Apache is running as
webserver_user=www-data

;Path all scripts have to be in
docroot=/var/www:${HOME}/public_html

;Path to chroot() to before executing script
;chroot=/mychroot

; Security options
allow_file_group_writeable=false
allow_file_others_writeable=false
allow_directory_group_writeable=false
allow_directory_others_writeable=false

;Check wheter script is within DOCUMENT_ROOT
check_vhost_docroot=true

;Send minor error messages to browser
errors_to_browser=false

;PATH environment variable
env_path="/bin:/usr/bin"

;Umask to set, specify in octal notation
umask=0077

; Minimum UID
min_uid=100

; Minimum GID
min_gid=100


[handlers]
;Handler for php-scripts
application/x-httpd-suphp="php:/usr/bin/php-cgi"

;Handler for CGI-scripts
x-suphp-cgi="execute:!self"

root@local [~]# cat /etc/apache2/mods-available/php5.conf

<FilesMatch ".+\.ph(p[345]?|t|tml)$">
    SetHandler application/x-httpd-php
</FilesMatch>
<FilesMatch ".+\.phps$">
    SetHandler application/x-httpd-php-source
    # Deny access to raw php sources by default
    # To re-enable it's recommended to enable access to the files
    # only in specific virtual host or directory
    Order Deny,Allow
    Deny from all
</FilesMatch>
# Deny access to files without filename (e.g. '.php')
<FilesMatch "^\.ph(p[345]?|t|tml|ps)$">
    Order Deny,Allow
    Deny from all
</FilesMatch>

# Running PHP scripts in user directories is disabled by default
#
# To re-enable PHP in user directories comment the following lines
# (from <IfModule ...> to </IfModule>.) Do NOT set it to On as it
# prevents .htaccess files from disabling it.
<IfModule mod_userdir.c>
    <Directory /home/*/public_html>
        php_admin_flag engine Off
    </Directory>
</IfModule>
Michael
  • 151
  • 6
0

fwiw on ubuntu 12.04 i took the following steps: added

:/usr/share/phpmyadmin

to the end of docroot in /etc/suphp/suphp.conf

added

<Directory /usr/share/phpmyadmin>
    suPHP_Engine on
</Directory>

to /etc/apache2/mods-enabled/suphp.conf

created a new virtual host

<VirtualHost *:80>
  ServerName phpmyadmin.example.com
  DocumentRoot /usr/share/phpmyadmin
  DirectoryIndex index.php
  <Directory /usr/share/phpmyadmin>
    Options FollowSymLinks
  </Directory>
  <directory /usr/share/phpmyadmin/setup>
    Order Deny,Allow
    Deny from All
  </directory>
  <directory /usr/share/phpmyadmin/libraries>
    Order Deny,Allow
    Deny from All
  </directory>
</VirtualHost>

did

chown pmauser:pmauser /usr/share/phpmyadmin
chown pmauser:pmauser /usr/share/phpmyadmin/*.php
chmod og-r /usr/share/phpmyamdin
chmod og-r /usr/share/phpmyamdin/*.php

which gets it mostly working.

I've not been able to figure out how to get rid of the error message asking for a blowfish_secret. Ubuntu scatters the config files through several directories and their /etc/phpmyadmin/apache.conf has

php_admin_value open_basedir /usr/share/phpmyadmin/:/etc/phpmyadmin/:/var/lib/phpmyadmin/

i'm not willing to add all those paths to the suphp docroot, and pma does not recognise /usr/share/phpmyadmin/config.inc.php

Steve
  • 101
  • 2