Index: [Article Count Order] [Thread]

Date:  Mon, 04 Sep 2006 08:44:27 -1000
From:  MuntadaNet Webmaster <webmaster (at mark) muntada.com>
Subject:  [coba-e:06746] Re: is our server secured?????? critical...
To:  coba-e (at mark) bluequartz.org
Message-Id:  <7.0.1.0.2.20060904083940.04c60da8 (at mark) muntada.com>
In-Reply-To:  <44FC2921.10601 (at mark) dogsbody.org>
References:  <200609041248578.SM01088 (at mark) Virus> <44FC2921.10601 (at mark) dogsbody.org>
X-Mail-Count: 06746

Just an FYI.  I believe if you have applications in which you put a 
username/password for database (MySQL) access, it is best that the 
php file that is in the public html directory /web/ have an include 
to the private directory of a user for the site (siteadmin type user) 
so that no one can read that file who might be perusing the file system:

/home/sites/www.domainanme.com/users/UserName/Private/

Doing an ls on that directory returns a permission denied unless you 
are the owner.

Additionally, you could always change the rw permissions on any file 
or directory.

-Rashid

At 03:24 AM 9/4/2006, you wrote:

>>i found the administrator of one domain can see the other dmain 
>>incase he is given SSH permission
>
>
>She can see but shouldn't be able to change anything under other 
>domains if you have set the permissions correctly.
>
>Dan
>

*****************************************************************
MuntadaNet Web Hosting and Web Design Services
http://www.muntada.com

Sales - sales (at mark) muntada.com
Support - support (at mark) muntada.com
Billing - billing (at mark) muntada.com

Main Office - 808-689-6092
Fax - (808) 356-0279
*****************************************************************