Re: suexec question
Stefan Wendt <[email protected]>
| Newsgroups | gmane.comp.web.fastcgi.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Barti,
>Stefan: I think that using patched suexec is best choice but not recomended by
>doc :)
>I am using grsecurity to chroot apache and php so level of security is
>higher than normal but can you tell me where can i find suexec patch?
>
>
>
>
Our hack is pretty straigt forward. We have just disabled the section
that checks for
the right DOCROOT. You can find the code here if you like:
http://www.crafted.de/fl/apache_2.0.53_suexec_HACK/
I just want to stress one more time that this partially defeats the purpose
of suexec from a security point of view.
glhf,
Stefan Wendt
___________________________________
fastcgi-developers mailing list
http://fastcgi.com/fastcgi-developers/