LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-01-2003, 10:25 AM   #1
lonny
Member
 
Registered: Nov 2003
Posts: 46

Rep: Reputation: 15
Apache webserver using root account.


Is it a good idea to be hosting a website while being logged in as root?
 
Old 12-01-2003, 10:31 AM   #2
szaroubi
Member
 
Registered: Oct 2003
Location: Montreal
Distribution: All/Any
Posts: 59

Rep: Reputation: 15
NO!!!!! NEVER!!!!11
Let say you write a buggy cgi script ..
and it gets compromised (which happens alot)
The hacker (cracker, whatchamacaler) will get root access to your machine....

Make the webserver run as a very very very restricted user.
 
Old 12-01-2003, 10:44 AM   #3
lonny
Member
 
Registered: Nov 2003
Posts: 46

Original Poster
Rep: Reputation: 15
So I should create a very restricted user and then edit httpd2.conf to have the homepage in this users directory. Or would it be better to give the user access to the default apache directory?

Last edited by lonny; 12-01-2003 at 10:54 AM.
 
Old 12-01-2003, 10:57 AM   #4
szaroubi
Member
 
Registered: Oct 2003
Location: Montreal
Distribution: All/Any
Posts: 59

Rep: Reputation: 15
Default directory is good ...
and default user is good ...
Just NOT root
And make shure that all files being server by the server and readble by the webserver's user.
 
Old 12-01-2003, 11:00 AM   #5
lonny
Member
 
Registered: Nov 2003
Posts: 46

Original Poster
Rep: Reputation: 15
Alright thanks ill give it a try!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How do I retain the PATH in the root account even when I switch to root using su? thearchitect Linux - Newbie 1 08-13-2005 12:02 AM
Apache webserver name karupt Linux - Networking 2 08-01-2004 11:55 PM
Apache Webserver 403 Forbidden Errors (User not in apache group?) Mankind75 Mandriva 4 07-08-2004 05:30 AM
apache webserver nooodles Linux - Networking 8 06-30-2004 01:04 AM
How do you limit bandwidth on your webserver account with a script??? timmy_laf Programming 1 01-08-2004 03:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration