From: "Marcos Rubinstein ALPA WWW" <[EMAIL PROTECTED]>
>
> starting apache as root.. but running it as web...
>
> User web
> Group web
>
> in /etc/httpd.conf (in the vs)...
>
> do something like above poses security problems?????
>
> TIA
>
> Cheers!
>
> Marcos
>


The Apache log files are still created as root, then. So any user with
access to httpd.conf can use Apache to e.g. overwrite /etc/passwd.



Reply via email to