note 35032 deleted from security.index by vincent
| From: | vincent@php.net | Date: | Sat, 16 Aug 2003 18:11:21 +0000 |
| Subject: | note 35032 deleted from security.index by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-54425@lists.php.net to get a copy of this message | ||
Note Submitter: dsimic (at) urc.bl.ac.yu
----
Why not chroot the whole Apache Web Server (or any other Web Server running under UNIX)?
After that, Apache will run inside chroot jail, limiting by that access to server's filesystem.
For me, that's the first step in the process of securing PHP installations.
Also, for people running Linux, look at www.grsecurity.net (don't take this as a sort of
marketing ;), which is a great kernel security-related patch.