{"id":239,"date":"2010-02-02T18:49:00","date_gmt":"2010-02-02T09:49:00","guid":{"rendered":"http:\/\/yamazon.org\/?p=239"},"modified":"2010-02-02T18:49:00","modified_gmt":"2010-02-02T09:49:00","slug":"linux-php-%e3%81%a7%e3%80%80sudo","status":"publish","type":"post","link":"https:\/\/apr20.net\/?p=239","title":{"rendered":"[LINUX] php \u3067\u3000sudo"},"content":{"rendered":"<p>\u30d6\u30e9\u30a6\u30b6\u304b\u3089PHP\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3001PHP\u30d7\u30ed\u30b0\u30e9\u30e0\u304b\u3089sudo\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u65b9\u6cd5\u3067\u3059\u3002<br \/>\n\u79c1\u306e\u5834\u5408\u306f\u3001\u624b\u5143\u306efedora\u304c\u52d5\u3044\u3066\u3044\u308b\u30b5\u30fc\u30d0\u3067\u8a66\u3057\u3066\u307f\u307e\u3057\u305f\u304c\u3001\u300canysense-devel\u300d\u3055\u3093\u306e\u8a18\u4e8b\u901a\u308a\u306b\u5b9f\u884c\u51fa\u6765\u307e\u3057\u305f\u306e\u3067\u3001\u3054\u7d39\u4ecb\u3001\u3068\u3044\u3046\u304b\u4eca\u5f8c\u306e\u81ea\u5206\u306e\u305f\u3081\u306b\u3082\u30e1\u30e2\u3057\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<blockquote><p>\n\u4ee5\u4e0b\u3001<a href=\"http:\/\/hogehack.blog80.fc2.com\/blog-entry-36.html\">\u53c2\u7167\u5143\u300canysense-devel\u300d\u3055\u3093<\/a>\u306e\u8a18\u4e8b\u3067\u3059\u3002<\/p><\/blockquote>\n<p><!--more--><\/p>\n<p>\u3054\u5b58\u77e5\u306e\u901a\u308aPHP\u304b\u3089\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u306b\u306fexec()\u3084system()\u7b49\u3092\u4f7f\u3048\u3070\u3044\u3044\u3093\u3067\u3059\u304c\u3001Apache\u306b\u5b9f\u884c\u6a29\u9650\u304c\u7121\u3044\u30d5\u30a1\u30a4\u30eb\u3092\u6271\u3046\u5834\u5408\u306fsudo\u3057\u3066\u304b\u3089\u5b9f\u884c\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<pre>&lt;?PHP\n$cmd = \"echo 'password' | sudo -S ls \/root\";\nexec($cmd, $output);\nprint_r($output);\n?&gt;<\/pre>\n<p>\u307f\u305f\u3044\u306b-S\u3092\u4ed8\u3051\u3066\u3084\u308c\u3070\u30d1\u30a4\u30d7\u3067\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u6e21\u3059\u3053\u3068\u304c\u51fa\u6765\u307e\u3059\u3002<br \/>\n\u3053\u3053\u3067\u5165\u529b\u3059\u308b\u306e\u306f\u3082\u3061\u308d\u3093apache\u304c\u52d5\u3044\u3066\u3044\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u30d1\u30b9\u30ef\u30fc\u30c9\u3067\u3059\u3002<br \/>\napache\u304c\u3069\u306e\u30e6\u30fc\u30b6\u30fc\u6a29\u9650\u3067\u52d5\u3044\u3066\u3044\u308b\u304b\u306fhttpd.conf\u306eUser\u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u3068Group\u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u3067\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<br \/>\n\u56e0\u307f\u306bCentOS5.1\u3067yum\u3067apache\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u5834\u5408\u306fapache\u3068\u3044\u3046\u30b0\u30eb\u30fc\u30d7\u306eapache\u3068\u3044\u3046\u30e6\u30fc\u30b6\u30fc\u3068\u3057\u3066\u52d5\u3044\u3066\u3044\u307e\u3059\u3002<br \/>\nPHP\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u306eexec()\u95a2\u6570\u3067\u547c\u3073\u51fa\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\u3082\u3053\u306e\u30e6\u30fc\u30b6\u30fc\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<br \/>\n\u4ee5\u4e0b\u3001Apache\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30e6\u30fc\u30b6\u30fc\u3092apache\u3068\u4eee\u5b9a\u3057\u3066\u66f8\u304d\u307e\u3059\u3002apache\u306f\u74b0\u5883\u306b\u5fdc\u3058\u3066\u9069\u5f53\u306b\u8aad\u307f\u66ff\u3048\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>sudo\u3059\u308b\u969b\u306b\u6e21\u3059\u30d1\u30b9\u30ef\u30fc\u30c9\u306fapache\u306e\u3082\u306e\u3067\u3059\u304c\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u306fapache\u30e6\u30fc\u30b6\u30fc\u306b\u306f\u30d1\u30b9\u30ef\u30fc\u30c9\u304c\u3042\u308a\u307e\u305b\u3093\u3002\u30d1\u30b9\u30ef\u30fc\u30c9\u304c\u7121\u3044\u5834\u5408sudo\u3067\u304d\u307e\u305b\u3093\u306e\u3067\u4f55\u3067\u3082\u3044\u3044\u306e\u3067\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u6307\u5b9a\u3057\u3066\u3042\u3052\u307e\u3057\u3087\u3046\u3002<\/p>\n<blockquote><p>sudo passwd apache<\/p><\/blockquote>\n<p>\u6b21\u306bapache\u30e6\u30fc\u30b6\u30fc\u304csudo\u3067\u304d\u308b\u3088\u3046\u306bsudoers\u30d5\u30a1\u30a4\u30eb\u3092\u7de8\u96c6\u3057\u307e\u3059\u3002\u30eb\u30fc\u30c8\u6a29\u9650\u3067<\/p>\n<blockquote><p>visudo<\/p><\/blockquote>\n<p>\u3068\u5165\u529b\u3059\u308b\u3068sudoers\u30d5\u30a1\u30a4\u30eb\u3092\u7de8\u96c6\u3067\u304d\u307e\u3059\u306e\u3067\u3001\u672b\u5c3e\u306b<\/p>\n<blockquote><p>apache  ALL=(ALL)       ALL<\/p><\/blockquote>\n<p>\u3068\u8ffd\u8a18\u3057\u307e\u3059\u3002\u3055\u3089\u306b<\/p>\n<blockquote><p>Defaults requiretty<\/p><\/blockquote>\n<p>\u3068\u3044\u3046\u884c\u3092\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8(\u884c\u982d\u306b#\u3092\u8ffd\u52a0)\u3057\u3066\u7aef\u672b\u3092\u6301\u305f\u306a\u3044\u30e6\u30fc\u30b6\u30fc\u304b\u3089\u306esudo\u3092\u8a31\u53ef\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3067apache\u30e6\u30fc\u30b6\u30fc\u304b\u3089sudo\u51fa\u6765\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u5192\u982d\u306ePHP\u30b9\u30af\u30ea\u30d7\u30c8\u3078\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u30a2\u30af\u30bb\u30b9\u3057\u3066\/root\u306e\u4e2d\u8eab\u304c\u898b\u308c\u305f\u3089\u6210\u529f\u3067\u3059\u3002<\/p>\n<p><a href=\"http:\/\/hogehack.blog80.fc2.com\/blog-entry-36.html\">http:\/\/hogehack.blog80.fc2.com\/blog-entry-36.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u30d6\u30e9\u30a6\u30b6\u304b\u3089PHP\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3001PHP\u30d7\u30ed\u30b0\u30e9\u30e0\u304b\u3089sudo\u30b3\u30de\u30f3\u30c9&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[102,154],"class_list":["post-239","post","type-post","status-publish","format-standard","hentry","category-old-blog","tag-linux","tag-sudo"],"_links":{"self":[{"href":"https:\/\/apr20.net\/index.php?rest_route=\/wp\/v2\/posts\/239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/apr20.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/apr20.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/apr20.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/apr20.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=239"}],"version-history":[{"count":0,"href":"https:\/\/apr20.net\/index.php?rest_route=\/wp\/v2\/posts\/239\/revisions"}],"wp:attachment":[{"href":"https:\/\/apr20.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/apr20.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/apr20.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}