Apache should not be running from root for sure. You have to have limited user for this task.
P.S You might find this guide useful. http://www.thegeekstuff.com/2011/03/apache-hardening/ On Tuesday, August 6, 2013, Stuart Bird wrote: > Hi All, > > Can anybody help me the current thinking on hosting a web site via Apache2 > (Lamp stack) in relation to where you place Document Root and which user > account you run it from? > > I seem to remember reading that the preferred option was to create a user > account specifically for running the server and creating the Virtual Hosts > etc. within that account rather than the default /var/www/ folders provided > by Apache2. Presumably so that you take everything from root? > > I can't now find the article so wondered if anyone had an opinion before i > go ahead. > > Thanks > > Stu > > > -- Regards, David Aizenberg Peterborough, United Kingdom +44 7867 223 359 www.linkedin.com/in/pixelshuck <http://about.me/PixelShuck>
_______________________________________________ Peterboro mailing list Peterboro@mailman.lug.org.uk https://mailman.lug.org.uk/mailman/listinfo/peterboro