Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Securing /usr/local/apache/proxy

Discussion in 'EasyApache' started by sh4ka, Oct 18, 2005.

  1. sh4ka

    sh4ka Well-Known Member

    Joined:
    May 12, 2005
    Messages:
    444
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    Uruguay
    cPanel Access Level:
    DataCenter Provider
    I saw this on this post: http://forums.cpanel.net/showthread.php?t=39020&highlight=hardening

    I mean, changing /usr/local/apache/proxy owner from nobody.nobody (as you can see below) to root.root.
    drwxr-xr-x 2 nobody nobody 4.0K Sep 4 00:00 proxy/

    Isn't that dangerous ? Have anyone tried, will this stop bad guys from that directory ?
    I know about mod security, phpsuexec, etc, etc.., I'm just going right to the point, is this good to prevent something ?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. chirpy

    chirpy Well-Known Member

    Joined:
    Jun 15, 2002
    Messages:
    13,470
    Likes Received:
    21
    Trophy Points:
    463
    Location:
    Go on, have a guess
    I'd suggest that you simply delete the proxy subdir, it's not needed and is a security risk.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. sh4ka

    sh4ka Well-Known Member

    Joined:
    May 12, 2005
    Messages:
    444
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    Uruguay
    cPanel Access Level:
    DataCenter Provider
    Thanks Chirpy, I'll try it..
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice