Forum Moderators: phranque

Message Too Old, No Replies

How to secure Apache with mod_php?

... running as a single user

         

stoffer

11:11 am on Feb 16, 2006 (gmt 0)

10+ Year Member



Hi everybody.

I’m running my website on a VPS with Apache 2.0.55 and PHP 5.1.2 with php installed as a module. (I also use MySQL).

There is no other users running on VPS/website but I’m a newbie to this stuff and need a bit of help to figure out how to setup things so they are fairly secure.

I have already done some of the stuff that the apache documentation mentions under “Security Tips”.

I’m using the Gallery2 photo software so running php in safe mode is not an option. I’m also using mod_rewrite, so the Gallery2 software needs to be able to write .htaccess. Finally, I’m currently using the php.ini which is more for developer use than running a tight ship. What is the most important to change here?

Sorry I know this is a very broad question but all kind of tips and help are most welcome.

Best Regards, stoffer
<snip>

[edited by: jdMorgan at 5:57 pm (utc) on Feb. 16, 2006]
[edit reason] No sigs or URLs, please. See TOS. [/edit]