Linux Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsLinux Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 19th, 2003, 07:50 AM
jerry_pclam jerry_pclam is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Posts: 21 jerry_pclam User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Question Setting Permissions of Directories under www for High Security

The situation is this:
Assume there is a directory called "wwwsub" under www root,
and there are 2 files inside it: "index.php" and "bye.html",
and the owner of wwwsub & the 2 files is "tom".

Now the question is:

For Internet users,
They can see bye.html & can see result of index.php via browsers.

For ALL Shell users(except root),
They cannot read/write the code inside index.php & bye.html.
"apache" group (has only 1 user: "apache") can read/write the code inside index.php & bye.html.
File owner "tom" can only have write permission(NOT Allowed to READ) on index.php & bye.html.
They cannot read the content of wwwsub.
"apache" group (has only 1 user: "apache") can read/write wwwsub.
File owner "tom" can only have write permission(NOT Allowed to READ) on wwwsub.

How can I set the permissions for wwwsub, index.php & bye.html such that
Internet users can browse the site but the restrictions for Shell users can also be enforced?

Last edited by jerry_pclam : March 19th, 2003 at 08:00 AM.

Reply With Quote
  #2  
Old March 19th, 2003, 08:01 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
There really is NO WAY you can stop shell users from reading those files unless you have just a single web site on the server. The most secure way would be to implement SuExec with minimal permission.
Next time you post something like this, it's better off that you show us the ls -Al output instead.

Last edited by freebsd : March 19th, 2003 at 08:54 AM.

Reply With Quote
  #3  
Old March 19th, 2003, 08:18 AM
jerry_pclam jerry_pclam is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Posts: 21 jerry_pclam User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Actually, I have not got such website setup yet.
It's just a plan by my boss.

In fact, my problem is:
Is it possible to turn off all permissions for Others (i.e. chmod ??0) and make "apache" as the file's group, but still allowing Internet users to be able to see the site?

Reply With Quote
  #4  
Old March 19th, 2003, 08:52 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
>> make "apache" as the file's group, but still allowing Internet users to be able to see the site?

Yes. But if you have multiple sites you just can't do it effectively because every local user can simply write a script (which will execute under apache) to mess around with each other files.

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsLinux Help > Setting Permissions of Directories under www for High Security


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT