Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[tlug] Prevent access shared server using PHP



Hi there

I got a VPS server with some limitations but it's cheap and powerful :)
I can't setup SElinux, I can't create encrypted file systems and I can't create nested virtual instances on it.

The same server will be used as production and pre-prod, so developers will be able to login by ssh/sftp/svn to update webfiles only. They are free to do whatever they want on pre-prod sites but final changes on production will be done by me.

My concern is about PHP. It's easy to restrict users access to certain folders by a good group/permission policy and also ssh-jail them but Apache will be the final user of those PHP scripts and Apache user doesn't have the same restrictions as a limited user. It can browse whatever is browsable for a common generic user.

Any suggestion to prevent this scenario?

Thanks!

Cheers

Pietro


--
- Pietro Zuco

- http://zuco.org
- http://freelex.eu
- Twitter: @drzuco



Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links