Hi everyone,
There is, I think, a big security problem: scripts are running under apache user. Due to that fact if someone decided to write a script in php, for example, so as to do uploads, the files will not be his but apche user ones. Is there any thing so as to prevent it? I think about suPhp which seems to be a good solution...
Please use forum search. There are already some threads concerning suPHP.
I haven't tried it yet, but it should not be hard to use suPHP if you correctly configure your server. This should not need any changes in ISPConfig.
Posts: 31,906
Thanks: 693
Thanked 4,196 Times in 3,212 Posts
As Oliver already stated. This is not an ISPConfig issue, it is a question how you configure your server. You can use either suPHP or SuEXEC + CGI-PHP to run PHP scripts under the web user.
Recent comments
10 hours 55 min ago
11 hours 53 sec ago
15 hours 59 min ago
22 hours 40 min ago
23 hours 29 min ago
1 day 43 min ago
1 day 5 hours ago
1 day 11 hours ago
1 day 15 hours ago
1 day 17 hours ago