Re: Security in PHP Many exploits use wget. So don't install wget, rename wget or make sure www-data can't use wget. An easy fix is setfacl -m u:www-data:--- /usr/bin/wget. There are many more wget alike programs. Use a very minimalistic chroot to ease administration.
__________________ With,
J. Jeyaseelan Everything Possible |