Re: [Security-Discuss] Exploits

Marko Vukovic <[email protected]> Tue, 11 Apr 2006 15:13:17 +0200
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Mon, 2006-04-10 at 13:50 -0400, Bob Puff@NLE wrote:
> I also noticed that the user apache has a /bin/sh for a shell.  A redhat machine I checked had 
> apache with a /bin/false shell.  Should this be done too?

Yes, Apache should definitely *not* have a shell.

____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________