Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-23, 13:40:45

Author Topic: suEXEC  (Read 3638 times)

0 Members and 1 Guest are viewing this topic.

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
suEXEC
« on: 2013-12-30, 13:55:49 »
I am wondering if KloxoMR uses suEXEC for cgi scripts?  Also wondering if CGI scripts can be run in any directory under /home/client/ or must it be /home/client/cgi?
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: suEXEC
« Reply #1 on: 2013-12-30, 14:57:16 »
SuExec is specific for apache. It's 'old-fashion' for security (access docroot based on 'user').

No need for fastcgi (declare as 'php-fpm' in Kloxo-MR, suphp and mod_php_ruid2/itk).
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: suEXEC
« Reply #2 on: 2013-12-30, 17:14:41 »
My concern is a client uploading a perl or bash script that can overcome the basedir restrictions you just added to php-fpm.  How to protect from other scripting languages?
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: suEXEC
« Reply #3 on: 2013-12-30, 17:21:50 »
My concern is a client uploading a perl or bash script that can overcome the basedir restrictions you just added to php-fpm.  How to protect from other scripting languages?
Latest version of 6.5.0/6.5.1 already fix this issue (basedir issue).
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: suEXEC
« Reply #4 on: 2013-12-30, 19:45:45 »
Yes, I see in php-fpm template.  This is only for PHP, it doesn't protect other scripting languages.  Example would be perl.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: suEXEC
« Reply #5 on: 2013-12-31, 02:16:52 »
Suexec still exist in apache config. You can see something like '<IfModule suexec.c> SuexecUserGroup admin admin </IfModule>' inside apache domain config.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: suEXEC
« Reply #6 on: 2014-01-01, 18:58:59 »
But doesn't there need to be a template, or it updated within each virtual host, or domain?

I am new to suEXEC and am confused slightly.  But from my reading it is a must in shared hosting to stop malicious scripts.

Please advise.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: suEXEC
« Reply #7 on: 2014-01-01, 20:03:25 »
Suexec already on in apache. You can see 'notice' in /var/log/httpd/error.log about suexec.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

 


MRatWork Affiliates:    BIGRAF(R) Inc.    House of LMAR    EFARgrafix

Page created in 0.071 seconds with 19 queries.

web stats analysis