PARANOID PERMISSIONS for apache?
| From: | Derek Sivers | Date: | Tue, 13 Feb 2001 18:00:03 +0000 |
| Subject: | PARANOID PERMISSIONS for apache? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-39453@lists.php.net to get a copy of this message | ||
Can anyone think of any downside to this idea?
Set Apache to run as user/group "www:www"
Set ownership of PHP files and folders to "www:www"
And set permissions to 700
So that ONLY Apache can read them.
Now - even if I give someone shell access to my box, or someone finds my personal login password, they still can't read my PHP passwords to MySQL.
(Of course I'd have to be user "www" when uploading changes/files to the website.)
Any other paranoid people tried this?
Any downside to it?