Re: apache + .htpasswd - bypass pwd check

From: Jedi/Sector One (j@pureftpd.org)
Date: 04/26/02


Date: Fri, 26 Apr 2002 23:15:52 +0159
From: Jedi/Sector One <j@pureftpd.org>
To: RSnake <rsnake@shocking.com>

On Fri, Apr 26, 2002 at 02:07:05PM -0700, RSnake wrote:
> cd ~john
> I don't have to know where it is.

  Unless your users have shell access, there's no reason to have anything
but a 'nobody' account in your /etc/passwd & co files.

  If you need entries for suexec to work, have fake ones, with no password,
no shell and /dev/null as a home directory. The only thing Apache+suexec
needs is to map uids to some user name.

  The real path to web pages of every virtual host is located in httpd.conf's
DocumentRoot directives. System accounts don't have to match.

> Chrooted jails are the only way to go.

  Indeed. Zeus has an handy feature to do this out of the box.
  

-- 
 __  /*-      Frank DENIS (Jedi/Sector One) <j@42-Networks.Com>     -*\  __
 \ '/     Secure FTP Server     \' /
  \/   Misc. free software   \/



Relevant Pages

  • Re: SAMBA and XP
    ... I use Samba to access shares from network 'nix boxes from ... In Windows, when you're a member of a Domain, you sent your authentication ... the home directory and drive mapping, ... and give it the same name and password as the account they ...
    (RedHat)
  • Re: Leopard: Advanced Options in Accounts not ready for prime time?
    ... When I created a regular user account I went back in to Advanced Options and changed the home directory for that user from /Users/ethant to /Volumes/Home/ethant. ... I'd expect that to create my basic account user in /Volumes/Home/ethant upon first login. ...
    (comp.sys.mac.system)
  • Re: Copying over a user account #2
    ... >>> The user now has permissions for all its own files, ... The desktop layout is in the home directory, at least on 10.4, so I do not ... never tried more than one account under 10.3, ... > difference -- I dragged the home directory over from the iBook to the G4 ...
    (comp.sys.mac.system)
  • Re: unpriviledge user to run a program
    ... Yes, least privilege, not "less than necessary privilege". ... having a special account associated with a network service opened up ... problem setting up a special home directory for each daemon ... To be honest, I don't use IRC. ...
    (comp.unix.shell)
  • Questions about system vs. user accounts...
    ... The problem I'm having is that I'll create a jabber account ... However...when I check the mysql user account that the RH9 rpms create, ... it has a bash shell and home directory of /var/lib/mysql...yet when I ... look in it's home directory there's no .bashrc. ...
    (RedHat)