Re: Using Samba to share Apache web root, securely

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 08/09/11 6:33 AM, m.roth@xxxxxxxxx wrote:
> What I've done, where developers, for example, need to put updated pages
> in, is to have the directories owned by apache/httpd, but the*group*  that
> they belong to, and make it group writeable.

you don't actually want apache/http to own ANY of the web content, it 
should all be read only from the webserver's perspective.   this way if 
the web server gets hacked, it can't be used to upload hostile content.



-- 
john r pierce                            N 37, W 122
santa cruz ca                         mid-left coast

_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos


[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux