LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-12-2006, 06:19 PM   #1
Eggert
LQ Newbie
 
Registered: Jul 2004
Posts: 9

Rep: Reputation: 0
Question Is this secure php setup for virtualhosting?


I'm running a webserver with multiple virtualhosts running php CMS software.

My server got hit hard a couple of months ago when a serious vulnerability was discovered in one of these php systems and my setup was really unsecure. So now I'm trying to secure php, but my googling has made me really confused -> about what is safe and what is not.

What I have done for now following a few recomendations is setting:

error_reporting, register_globals and magic_quotes OFF

disable_functions to system,exec,passthru,popen,escapeshellcmd,shell_exec

and each Virtualhost has php_admin_value open_basedir set to its web directory via httpd.conf

Now, in hope of someone wiser than me will read this and care to guide me, I ask.
Is this solution somewhere close to limiting each virtualhosts php access to it's directory?
Are there maybe some more functions I should consider adding to disable_functions directive?
Should I opt for running php as CGI with suExec? As I understand it (remember ), there is a considerable degrade in performance, and a bunch of new security considerations with that, and I'm not keen on opening any Pandora's boxes.

Any and all suggestions/questions are very much appreciated.

TIA, Eggert Johannesson
 
Old 02-14-2006, 08:21 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'll recycle a recent post if I may. Have a look at my response to the question "Are there any other suggestions you can make?".
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is this setup reasonably secure? The_JinJ Linux - Newbie 3 10-04-2005 08:34 PM
setup a secure proxy darkleaf Linux - Security 2 07-13-2005 07:58 PM
The correct/secure way to setup a webserver? ]SK[ Linux - Software 5 02-11-2005 02:34 AM
Squid and virtualhosting lil_drummaboy Linux - Networking 0 01-30-2005 04:16 AM
Trying to setup a secure webserver pyrombca Linux - Software 0 09-02-2003 05:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration