Solved

Help with php parsing on apache

Posted on 2011-02-22
3
606 Views
Last Modified: 2013-12-13
Is it a good idea to run suEXEC when your using fcgi to parse your php files on apache?
0
Comment
Question by:sparingatom
  • 2
3 Comments
 
LVL 3

Accepted Solution

by:
wwwdeveloper2 earned 500 total points
Comment Utility
what issues are you specifically worried about?  Security, stabilization, or what?

Running suEXEC is a good idea for running the applications as different users, especially if you are in a shared hosting environment.  Just understand that there are a lot of assumptions that you are familiar with your system's security or using suExec can open a lot of holes.  

Here is a good article that might be worth you reading if you are planning to go this route.  Just be safe and you can definitely run with this type of setup.

http://httpd.apache.org/docs/current/suexec.html

0
 
LVL 2

Expert Comment

by:schwomp
Comment Utility
Hello!

> or using suExec can open a lot of holes.  

Could you explain?

I am using suexec with fcgid and it works like a charm.

Bye
0
 
LVL 3

Expert Comment

by:wwwdeveloper2
Comment Utility
Schwomp -  Check the link I submitted - It is way too much to explain here, but if you want to submit a question maybe it would more help.  

"Used properly, this feature can reduce considerably the security risks involved with allowing users to develop and run private CGI or SSI programs. However, if suEXEC is improperly configured, it can cause any number of problems and possibly create new holes in your computer's security. If you aren't familiar with managing setuid root programs and the security issues they present, we highly recommend that you not consider using suEXEC."  - From Apache
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Developers of all skill levels should learn to use current best practices when developing websites. However many developers, new and old, fall into the trap of using deprecated features because this is what so many tutorials and books tell them to u…
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now