I know I mentioned this before and even emailed support about it but that is the only thing me and my friends find wrong with da is the way it runs apache by apache user and group. A pretty dangerous setup, if someone uploaded a php shell they could write to anything and rise above the home folder.
I wish they would change it to nobody or www-data. The way it is now is dangerous and insecure.
I don't know if anyone agrees with me on this or not but the security minded people I know do. The apache user has way too many privileges to be ran this way.
I wish they would change it to nobody or www-data. The way it is now is dangerous and insecure.
I don't know if anyone agrees with me on this or not but the security minded people I know do. The apache user has way too many privileges to be ran this way.