<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'DejaVu Sans'; font-size:9pt; font-weight:400; font-style:normal;">Hi,<br>
<p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; -qt-user-state:0;"><br></p>better would be to let the subdir under /var/www to be owned by user.apachegoup and set to 755.<br>
<p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; -qt-user-state:0;"><br></p>This way, each user can manage his contents and apache can only read them and show their contents to visitors.<br>
<p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; -qt-user-state:0;"><br></p>Giorgio<br>
<p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; -qt-user-state:0;"><br></p>Il Monday 17 August 2009 14:18:38 Roy Sigurd Karlsbakk ha scritto:<br>
> On 17. aug.. 2009, at 13.43, Armindo Silva wrote:<br>
> > Shouldn't be owned by www-data so apache can write there?<br>
><br>
> No. Allowing the apache user to change or delete its website is no<br>
> good and allows for much easier hacking/defacing the site(s) on the<br>
> box. If the apache user cannot write to /var/www, a security bug in<br>
> the web server won't allow the hacker write access to /var/www, so<br>
> less harm done.<br>
><br>
> roy<br>
> --<br>
> Roy Sigurd Karlsbakk<br>
> (+47) 97542685<br>
> roy@karlsbakk.net<br>
> http://blogg.karlsbakk.net/<br>
> --<br>
> I all pedagogikk er det essensielt at pensum presenteres<br>
> intelligibelt. Det er et elementært imperativ for alle pedagoger å<br>
> unngå eksessiv anvendelse av idiomer med fremmed opprinnelse. I de<br>
> fleste tilfeller eksisterer adekvate og relevante synonymer på norsk.<br>
<p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; -qt-user-state:0;"><br></p><p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; -qt-user-state:0;"><br></p></body></html>