On 2/27/06, Tarus Balog <[EMAIL PROTECTED]> wrote:
>
> On Feb 27, 2006, at 3:53 PM, Rick DeNatale wrote:
>
> > I haven't used it myself, but I'd recommend pondering this advice from
> > the folks who bring you mod_auth_pam
> > http://pam.sourceforge.net/mod_auth_pam/shadow.html
>
> Came across that link getting it to work. (grin)
>
> On Debian there is already a "shadow" group, so you just have to add
> www-data to it. No need to change the group that apache uses to run.

Right, but then keep in mind that anything which runs as www-user has
access to /etc/shadow which can be arbitrary cgi code.

--
Rick DeNatale

Visit the Project Mercury Wiki Site
http://www.mercuryspacecraft.com/
--
TriLUG mailing list        : http://www.trilug.org/mailman/listinfo/trilug
TriLUG Organizational FAQ  : http://trilug.org/faq/
TriLUG Member Services FAQ : http://members.trilug.org/services_faq/

Reply via email to