Curt Zirzow wrote:

> * Thus wrote Joachim ([EMAIL PROTECTED]):
>> > Yes that is a big security hole. There are some hosting solutions,
>> > I cant really help you there, but this concept I think should work
>> > would be:
>> > [...]
>> > user/group: $virtualuser/apache
>> 
>> Hmm, well. It may be "more" secure, but there is still the problem, that
>> every $virtualuser can access the files. You still have to hope that
>> there is now "bad" $virtualuser.
> 
> perhaps a little more detail on how things would be set up:
> 
> Folder strucure                 user/group         permissions
> /www/virtual1-domain.com/www/   virtual1/apache    0770
> /www/virtual2-domain.com/www/   virtual2/apache    0770
> 
> thus virtual1 cant touch virtual2's files and vice versa.

Oh, yes, thanks you opened my eyes! :-)

 Joachim



-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to