[EMAIL PROTECTED] Apache 2.2 security concern

2007-05-11 Thread Sam Lavitt
I am wondernig if apache 2.2 has a means to prevent a user with a site hosted on the server, from accessing another users files. (e.g. I have /hosting/user1, and I don't want him to be able to run a script to open /hosting/user2/password-file) I read someplace that there was a mpm for apache

Re: [EMAIL PROTECTED] Apache 2.2 security concern

2007-05-12 Thread Sam Lavitt
Nick Kew wrote: On Fri, 11 May 2007 23:01:12 -0500 Sam Lavitt <[EMAIL PROTECTED]> wrote: I am wondernig if apache 2.2 has a means to prevent a user with a site hosted on the server, from accessing another users files. That's the operating system's business.

Re: [EMAIL PROTECTED] Apache 2.2 security concern

2007-05-12 Thread Sam Lavitt
Res wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sat, 12 May 2007, Dragon wrote: PHP provides for this directly. There is a restrict_base_dir setting that can be applied to each virtual host that prevents users from accessing anything outside of the specified directory tree.

Re: [EMAIL PROTECTED] Keeping hackers out of /dev/smh

2007-05-16 Thread Sam Lavitt
Marc Perkel wrote: Graeme Fowler wrote: On Wed, 2007-05-16 at 05:46 -0700, Marc Perkel wrote: What's the best way to keep hackers out of /dev/shm? I'm getting the script kitties installing IRC bots. Mount /dev/shm noexec. More importantly, close the holes the script kiddies are g

Re: [EMAIL PROTECTED] Keeping hackers out of /dev/smh

2007-05-16 Thread Sam Lavitt
Joshua Slive wrote: On 5/16/07, Marc Perkel <[EMAIL PROTECTED]> wrote: I was hoping for a more specific answer. If I could have done that I wouldn't be here asking how to do it. Well, your original question was a little like "There's some money missing from my dresser drawer; how do I stop

Re: [EMAIL PROTECTED] Is Win32 Apache ready for prime time?

2007-05-29 Thread Sam Lavitt
Foo JH wrote: Hello all, I've been using Apache 2.2 for Win32 (with modperl) for some time. But one thing bugs me quite often. That is: once in a while (quite randomly), Apache will produce the following error: [Mon Mar 05 21:19:47 2007] [notice] Parent: child process exited with status 32

Re: [EMAIL PROTECTED] Is Win32 Apache ready for prime time?

2007-05-29 Thread Sam Lavitt
Foo JH wrote: Hey Sam, Just to check: are you running Apache 2.2 only from the binary, w/o any PHP/ modperl addons? Ummm, actually Win32 Apache 2.2 is *VERY* stable, my current server is running on an XP home box (so shoot me) and has been up over six months! I have never seen anything su

Re: [EMAIL PROTECTED] Is Win32 Apache ready for prime time?

2007-05-29 Thread Sam Lavitt
Foo JH wrote: I'm running it with both PHP5 and mod_perl, without any problems, and I am using the binary (no recompile here, no M$ visual studio) A success story! Perhaps you can share with me your setup process: 1. Are you installing from WAMP, or via direct binary download from Apache?