store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 2:49 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: Safe_mode needed with ASL?
Unread postPosted: Thu Oct 11, 2007 1:35 am 
Offline
Forum User
Forum User

Joined: Wed Nov 23, 2005 8:49 am
Posts: 49
I´ve always onfigured safe_mode as on with all webhosting servers. Now, I will start using SWSOFT´s Sitebuilder along with PLESK 8.2 which requires safe_mode to be sat to off.

Question is, what are the alternatives to safemode to keep the server from beeing hacked. Using ASL as well, but I do not think that it compensates for safe_mode?

Any suggestiongs would be welcome. Thanks.


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Oct 11, 2007 7:26 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
I'd just set the global safe_mode setting (in /etc/php.ini) to On and disable safe_mode on domains that don't function under safe_mode.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Oct 11, 2007 7:30 am 
Offline
Forum User
Forum User

Joined: Wed Nov 23, 2005 8:49 am
Posts: 49
Thanks breun. That limits the nuber of domains that can be used for an exploit, but the problem is still there.


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Oct 11, 2007 7:48 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
safe_mode is no guarantee against exploits. In fact, I believe safe_mode will be removed in PHP 6 as it gives a false sense of security. That doesn't mean it is completely useless though, it will stop some bad thing from happening. On the other hand, it also perfectly possible to have exploitable code run under safe_mode.

I'm pretty sure you cannot audit all code that will run on your server and in fact you will never be sure code cannot be exploited. I think using security tools like ASL provides and having a usable safe_mode policy is in most cases all you can practically do.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Oct 11, 2007 8:23 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Its all about security in depth.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group