in reply to Structuring a Web site and security issues
If you're tring to get Apache to run under your user id (so that it can access files and directories owned by you), you should take a look at the suexec mechanism. If you're further looking to improve your security, maybe consider running apache in a chrooted/jailed environment. As for the datbase logs, you should never log username/password information (unless you're debugging), if you further want to secure your logs you could write to a named pipe and have another process (running as a different user) read from the pipe and log to a file not readable by your user.
Securing a website properly is a rather large topic and covers lots of areas (network security, host security, programming securely). There are lots of books on the subject though.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Structuring a Web site and security issues
by bradcathey (Prior) on Dec 26, 2005 at 18:06 UTC | |
by tirwhan (Abbot) on Dec 26, 2005 at 19:10 UTC |