Hacker Times
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Dylan16807
on Jan 13, 2019
|
parent
|
context
|
favorite
| on:
GoDaddy injecting JavaScript into websites and how...
The situation with default file permissions is already terrible enough that no host should ever have o+x on home directories. And once you remove that, it doesn't matter if everything inside is 777.
naniwaduni
on Jan 13, 2019
[–]
This doesn't work for setups with e.g. a single apache instance running as www-data.
Dylan16807
on Jan 13, 2019
|
parent
[–]
Add the apache user to every customer's group. It can get into the files but no other users can.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: