[wellylug] Apache2 / 403

David Murray newslists at electronincantation.net.nz
Thu Mar 9 11:35:25 NZDT 2006


On Thu, 9 Mar 2006, Grant McLean wrote:

>>> Why is your contents directory owned by root?
>> Good question . RPM install. Should I change it to apache:apache ? or nobody ?
>
> There's nothing wrong with having content owned by root.  The thing you
> want to avoid is having content owned by the user that the Apache
> process runs as.  In the event that someone managed to exploit a problem
> in your Apache process then you don't want that process to have write
> access to the disk.

That's a very good point. Thanks for mentioning it.


Cheers

David Murray




More information about the wellylug mailing list