From owner-freebsd-security Tue Jan 22 23:53:11 2002 Delivered-To: freebsd-security@freebsd.org Received: from thorium.datanet.hu (thorium.datanet.hu [194.149.0.116]) by hub.freebsd.org (Postfix) with SMTP id 8FD8937B400 for ; Tue, 22 Jan 2002 23:53:00 -0800 (PST) Received: (qmail 27110 invoked by uid 5001); 23 Jan 2002 07:52:58 -0000 Received: from localhost (sendmail-bs@127.0.0.1) by localhost with SMTP; 23 Jan 2002 07:52:58 -0000 Date: Wed, 23 Jan 2002 08:52:58 +0100 (CET) From: sj@datanet.hu To: Robert Herrold Cc: Buliwyf McGraw , Subject: Re: Creating users from the web In-Reply-To: <001701c1a3c3$19ab6e20$6c01a8c0@mpcsecurity.com> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org You may try another approach: Build a simple cgi script that will put data about the new user to a file or database. Then make an entry in root's crontab to script regularly to process the file or database mentioned above. This way you don't need setu(g)id programs. Of course, you need strong authentication and carefully designed cgi script and a bullet-proof command involved from cron SJ. On Tue, 22 Jan 2002, Robert Herrold wrote: > Commercially, you can take a look at billmax (1st 100 users free). An oldie > I used to use was called URIBS from n2h2 > > > ----- Original Message ----- > From: "Buliwyf McGraw" > To: > Sent: Tuesday, January 22, 2002 8:39 PM > Subject: Creating users from the web > > > > > > Hello, i want to build a system to create users from a web interface. > > I tried to use the su_exec function of apache but it doesn't support > > run programs "as root" or execute setuid programs. > > I really need that the system work by the web... i know that it could > > be insecure, but anyway, i have to do it. > > Any sugestions? > > Thanks for any help. > > > > ======================================================================= > > Buliwyf McGraw > > Administrador del Servidor Libertad > > Centro de Servicios de Informacion > > Universidad del Valle > > ======================================================================= > > > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > > with "unsubscribe freebsd-security" in the body of the message > > > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message