Thread: Security in PHP
View Single Post
  #148 (permalink)  
Old 04-23-2008, 11:56 PM
Jeyaseelansarc Jeyaseelansarc is offline
D-Web Genius
 
Join Date: Mar 2007
Location: Chennai
Posts: 1,162
Jeyaseelansarc is on a distinguished road
Send a message via AIM to Jeyaseelansarc
Default Re: Security in PHP

Many exploits use wget. So don't install wget, rename wget or make sure www-data can't use wget. An easy fix is setfacl -m u:www-data:--- /usr/bin/wget. There are many more wget alike programs. Use a very minimalistic chroot to ease administration.
__________________
With,
J. Jeyaseelan

Everything Possible
Reply With Quote