LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE
User Name
Password
SUSE / openSUSE This Forum is for the discussion of Suse Linux.

Notices


Reply
  Search this Thread
Old 04-29-2005, 08:29 PM   #1
narc
Member
 
Registered: Aug 2004
Location: Montréal
Distribution: Linux from scratch
Posts: 68

Rep: Reputation: 15
A question on Apache accessing root files


Hello.

I am worried about the default settings on Suse 9.3's apache. It is able to read files that are part of user root, group root. Is this normal ? Normally, the precise access path is /srv/www/htdocs/. But should I worry that it may also access other dirs as well and thus, having no security at all ?

Any help appreciated.

narc.
 
Old 04-29-2005, 08:40 PM   #2
AltF4
Member
 
Registered: Sep 2002
Location: .at
Distribution: SuSE, Knoppix
Posts: 532

Rep: Reputation: 31
SUSE usually runs apache as user "wwwrun", group "www"
check if this user/group can read the files in /srv/www/htdocs/
 
Old 04-29-2005, 09:13 PM   #3
narc
Member
 
Registered: Aug 2004
Location: Montréal
Distribution: Linux from scratch
Posts: 68

Original Poster
Rep: Reputation: 15
Thanks. But let me rephrase this:

Well, yes. It *does* read the files in /srv/www/htdocs. It actually reads *all* files in that directory regardless of user or group ownership (root, wwwrun, www, users, etc.). That is what worries me. My question was: do I need to worry that apache might read ouside of this directory which would compromise security ? In other words, is it preferable that apache may only read files with specific ownership so that if it does read outside of /srv/www/htdocs, it would do miinmal damage ? Or is this overly paranoid ? If not, I need to know how to set it for specific ownerships.

Let me know.


narc.
 
Old 05-01-2005, 10:25 AM   #4
AltF4
Member
 
Registered: Sep 2002
Location: .at
Distribution: SuSE, Knoppix
Posts: 532

Rep: Reputation: 31
If everything goes well (correct configuration, no bugs in CGI programs, etc), apache does only server out of your DocumentRoot (/srv/www/htdocs).

Additional security and a bit of paranoia may help you survive in a hostile world :-)
You can set secure permissions, run apache in a chroot jail or in a virtual unix server (UML - UserModeLinux, XEN virtual machine).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
creating files/folders accessing root folder remotely NapalmBob Linux - Networking 2 09-24-2004 10:47 PM
Problem accessing subdirs from doc root on Apache server ph0ngwh0ng Linux - Newbie 4 04-24-2004 12:02 PM
accessing files & directories - a really simple question hildog Linux - Newbie 6 10-12-2003 06:17 PM
Question on Apache Log Files JLDixon Linux - Software 1 10-12-2003 11:03 AM
Stop root from accessing my files MasterC Linux - General 10 10-20-2002 12:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE

All times are GMT -5. The time now is 12:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration