PARANOID PERMISSIONS for apache?

From: Date: Tue, 13 Feb 2001 18:00:03 +0000
Subject: PARANOID PERMISSIONS for apache?
Groups: php.general 
Request: Send a blank email to php-general+get-39453@lists.php.net to get a copy of this message
Can anyone think of any downside to this idea? Set Apache to run as user/group "www:www" Set ownership of PHP files and folders to "www:www" And set permissions to 700 So that ONLY Apache can read them. Now - even if I give someone shell access to my box, or someone finds my personal login password, they still can't read my PHP passwords to MySQL. (Of course I'd have to be user "www" when uploading changes/files to the website.) Any other paranoid people tried this? Any downside to it?

« previous php.general (#39453) next »