|
-
August 12th, 2011, 06:41 PM
#3
You're adding levels of confusion to the user, and overcomplicating the system.
I'd rather lock down Apache and just grant broad access to the service. Use rinetd to allow Apache to run on a non-priveleged port, eliminating any paths to root. Drop any uneeded modules, configure SELinux to compartmentalize Apache and PHP's acess to the system, etc. Since only *trusted* users are going to be on the system, you don't have to worry about the broad security issues of a shared hosting environment. Instead, you can concentrate on mitigating web vulnerabilities.
You can use a VPN to allow for remote service access for SSH, FTP, and anything else you need on the administrative end.
Real security doesn't come with an installer.
Similar Threads
-
By ThePreacher in forum Miscellaneous Security Discussions
Replies: 17
Last Post: December 14th, 2006, 09:37 PM
-
By DrewDodson89 in forum General Programming Questions
Replies: 1
Last Post: November 7th, 2006, 02:12 AM
-
By hatebreed2000 in forum AntiOnline's General Chit Chat
Replies: 1
Last Post: March 14th, 2003, 06:36 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|