Results 1 to 3 of 3

Thread: Apache user for cgi scripts/best security

  1. #1
    Senior Member
    Join Date
    Apr 2002
    Posts
    417

    Apache user for cgi scripts/best security

    Hi,

    I just installed Apache2.0 and it's using nobody as the deamon user. Is this ok or should I change it to something else? Should I change the permissions on teh scripts/pages to 'other' have no rwx, who should be owner

    thanx

  2. #2
    Mentor coltrane's Avatar
    Join Date
    May 2001
    Location
    North Carolina
    Posts
    1,390

    Re: Apache user for cgi scripts/best security

    If the http daemon is running as wwwrun, then Id maintain the ownership of the cgi scripts as another user, just in case you are compromised.

    Of course if your root access is compromised then that pretty much negates the issue.

    Basically, good security means that you have to remain paranoid.


  3. #3
    Moderator
    Good Guru
    Compunuts's Avatar
    Join Date
    May 2001
    Location
    California
    Posts
    3,935

    Re: Apache user for cgi scripts/best security

    Well CGI should be run as nobody or unless you will have to authenticate all your users....

Similar Threads

  1. Microsoft Security Bulletin MS05-014
    By regix in forum Windows - General Topics
    Replies: 0
    Last Post: 02-26-2005, 01:26 AM
  2. Microsoft Security Bulletin MS05-008
    By regix in forum Windows - General Topics
    Replies: 0
    Last Post: 02-26-2005, 01:23 AM
  3. How to Set Your Internet Explorer Security and
    By The Donald in forum Windows - General Topics
    Replies: 1
    Last Post: 01-04-2005, 09:31 PM
  4. List of fixes included in Windows XP SP2
    By regix in forum Windows - General Topics
    Replies: 6
    Last Post: 01-03-2005, 10:44 PM
  5. Live Communications Server 2005 Glossary
    By regix in forum Windows - General Topics
    Replies: 0
    Last Post: 01-01-2005, 08:16 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •