Home > other > Change the user and group that PHP executes as

Change the user and group that PHP executes as

January 6Hits:0
Advertisement

Hi all, i'm hardening a web server with apache.
PhpsecInfo suggest me to do this:

"Change the user and group that PHP executes as. If you're using the Apache module, you'll need to change what user Apache runs as with the User and Group directives"

How can I do it? On my server i got just root user and root group.
I can create new users and new group but how can I tell to system to use that user to execute PHP?
Thanks a lot.

Answers

If you're using mod_php, you must change the User and Group directives in the apache configuration.

To create users and groups, take a look at

Code:

man groupadd
man useradd

Thanks Falko, the problem is that i don't know how to change the User and Group directives in the apache configuration. I know how to add users and group but where I can change? apache2.conf? Thanks.
Depends on your distribution. For Debian/Ubuntu, it's /etc/apache2/apache2.conf, and for Fedora/CentOS, it's /etc/httpd/conf/httpd.conf.

Tags:

Related Articles

  • Change the user and group that PHP executes asJanuary 6

    Hi all, i'm hardening a web server with apache. PhpsecInfo suggest me to do this: "Change the user and group that PHP executes as. If you're using the Apache module, you'll need to change what user Apache runs as with the User and Group directives&qu

  • Users group has Read & Execute access to C:\Windows file & Microsoft SQL ServerOctober 2

    Just wonder is it the systems behavior for window server 2008 R2 Standard to allow users group has Read & Execute access to C:\Windows file & Microsoft SQL Server? I tried to modified the permission for user groups in both the files to Read only,

  • Why the S_ISUID and S_ISGID mode bits got cleared when the owner or group of an executable file are changed by an unprivileged userOctober 8

    I was reading the man page of chown. I don't understand why S_ISUID and S_ISGID mode should be cleared when the function returns successfully. --------------Solutions------------- I think you're pointing to this from the man page: When the owner or g

  • Why doesn't the owning group get the executable bit? January 1

    This question already has an answer here: Can not explain ACL behavior 1 answer facl ignoring the "x" permission but only on files 2 answers Playing with ACL's: [[email protected] web]# pwd /media/web [[email protected] web]# ll -d drwxr-xr-x. 2 root root 4096 Ja

  • Why assign write and execute permissions to a group when executing web scripts?April 5

    If I have a script that is to be executed by the nobody user, why is there a need to assign group read and execute permissions. For example in the article at http://www.zzee.com/solutions/unix-permissions.shtml, it notes that the permission 755 shoul

  • How to set a directory's permissions for group read/execute accessFebruary 20

    I am running Arch and have just install XAMPP. I have change changed my document root to /srv which is a separate EXT4 partition. I have set the Apache HTTP server to use a group called "http". I have added my user to the http group. I want ever

  • IIS + Integration Windows Authencation: is read/execute permissions for Authenticated_Users safe?November 5

    I have an enterprise web application that will integrate with a single sign on (SSO) service via Integrated Windows Authentication (IWA). The SSO service is providing authentication only (not authorization). This web application will handle authoriza

  • Windows 7 taskbar items not grouping properlyApril 26

    I don't understand the Windows 7 taskbar behaviour. For some programs it will not group the running instances, or it will group some of them but not all. I have set the taskbar items to "always combine", but this has not helped. It seems possibl

  • Can't read directory owned by my groupJune 11

    I moved the postgres data directory to a separate partition and it works great. The directory is owned by postgres user and postgres group. d-wx------ 11 postgres postgres 4.0K 2010-06-11 08:28 data/ I added myself to the group > sudo addgroup me pos

  • Win2003 Folder sharing : Group permissions not working while user permissions workAugust 16

    I'm very new to windows server. I'm a software engineer but since we don't have a real sysadmin I'm supposed to figure out everything that is slightly computer related (you know how it is...). I need to set permissions for a group on a specified fold

  • How do I execute a script or program on Windows Shut DownNovember 12

    I want to run a exe or bat file when window shut down? I want to unmount few drives , which are mounted by my application , when user shutdown the system. For that I need to execute another exe on shutdown, which will disconnect drives mounted by my

  • Can anyone see why dropbox won't execute in a text only install on ubuntu server using a system user account?May 2

    I've been trying to set up dropbox on an ubuntu 10.04.2 server to use for backup. I don't want dropbox to be tied to my user account on the server as someone may take over as administrator with a different user account next year. To achieve this I've

  • What is the difference between the 'sudo' and 'admin' group?May 17

    I noticed that two groups are granted similar-looking permissions in /etc/sudoers: # Members of the admin group may gain root privileges %admin ALL=(ALL) ALL # Allow members of group sudo to execute any command %sudo ALL=(ALL:ALL) ALL My user account

  • Default groups for user in Ubuntu 11.04?May 22

    I accidentally removed my user from some groups yesterday because of some virtualbox issues and today I couldn't use sudo to do anything and had to use a livecd to edit sudoers. Anyway I want to edit the user to be in the same groups it would be in t

  • "CREATOR OWNER" NTFS group always has special permissions in windowsSeptember 15

    I was working on setting up a network share (see below story) and I ran into some odd behavior with NTFS permissions. The "CREATOR OWNER" object seems to only be able to list "Special" permissions in the "Security tab". No ma

  • permission for the `www-data` user to execute a binary fileOctober 20

    How can I give permission for the www-data user of Ubuntu machine to execute a command installed in /usr/local/bin ? --------------Solutions------------- First of all, run the following command: ls -l /usr/local/bin/_filename_ If there is no "x"

  • How do I allow a group (except one user in that group) to use sudo without a password?November 12

    How do I allow an entire group, except a certain user in that group, to use sudo without providing password? --------------Solutions------------- It is enough to put the user line after th group line: %admin ALL=NOPASSWD: ALL enzotib ALL=(ALL:ALL) AL

  • Deleted Myself from Admin Group - Now Getting Error usermod: cannot lock /etc/passwd; try again later November 16

    Possible Duplicate: Cannot lock '/etc/group' in recovery mode I have a laptop with Ubuntu 11.10 that is shared between myself and two other family members. My user id was setup as the only "Administrator" on the laptop. The other users were setu

  • Creating files through mounted Samba share makes them executable by userMarch 4

    I created a Samba share on my Ubuntu virtual machine and mounted the share on my Windows 7 host using net use W: \\blog.localhost\blog. When editing or creating any file it sets the perms to -rwxr--r--, and it should be setting it to -rw-r--r--. I ne

  • let users group do "sudo -u username chown"March 26

    I would like to edit /etc/sudoers so that group users can execute (only) /bin/chown as user dummy. How might this be done? --------------Solutions------------- The chown command requires root privileges. It will not run as any other user. You could r

Copyright (C) 2017 ceus-now.com, All Rights Reserved. webmaster#ceus-now.com 14 q. 0.441 s.