Hi Folks. I have some basic questions about using the suexec, and suphp functions. I have been having periodic problems with script kiddies exploiting some weak scripts on my machine. I can identify the offending processes and stop them, then find some files that were put into /tmp and get rid of them, but the problem is that I can't drill down through the logs and find out exactly which user account was causing the weakness or the problem. Everything has a record of "nobody".
Now I have done some reading and research and I believe that suexec and suphp will wrap these rogue scripts and make them be more identifiable. I guess the biggest question that I have is, if I hadn't set up suexec or suphp from the beginning, will all of my perl and php scripts break as soon as I implement suexec/suphp? I had been hesitant in the past because I have a lot of existing scripts and not a lot of time to do troubleshooting for broken scripts on every site that I administer. Is it really going to be that bad?
Any other advice anyone might have on this topic would be greatly appreciated. Thanks.
Now I have done some reading and research and I believe that suexec and suphp will wrap these rogue scripts and make them be more identifiable. I guess the biggest question that I have is, if I hadn't set up suexec or suphp from the beginning, will all of my perl and php scripts break as soon as I implement suexec/suphp? I had been hesitant in the past because I have a lot of existing scripts and not a lot of time to do troubleshooting for broken scripts on every site that I administer. Is it really going to be that bad?
Any other advice anyone might have on this topic would be greatly appreciated. Thanks.