Quantcast
Channel: Nginx Forum
Viewing all articles
Browse latest Browse all 53287

apache+php-fpm and security in shared enviroment compared to apache+suexec+mod_fastcgi

$
0
0
I've been using apache with suexec and mod_fcgid. It starts php handlers as
selected system user and listen to request via PIPES (fastcgi protocol). It
works well but can't share opcode between many handlers.
I've been investigating php-fpm aproach. What I can see is that in only
runs as tcp fastcgi server (like 127.0.0.1:9999) (under selected system
user) and apache has to conenct to it using FastCGIExternalServer or
fastcgi proxy mod. What the hell will stop other local users from
connecting to 127.0.0.1:9999 and passing their own code to handler that is
running as other system user? That seems totaly not secure in shared
enviroment. Am I missing something or what?

--

---
You received this message because you are subscribed to the Google Groups "highload-php-en" group.
To unsubscribe from this group and stop receiving emails from it, send an email to highload-php-en+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.

Viewing all articles
Browse latest Browse all 53287

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>