We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21483
    • 32 Posts
    http://wiki.modxcms.com/index.php/Securing_your_site

    In that article his talking about suPHP and PHPSuexec. Can anybody do the mods he suggest, or does it require anything special on your server to run suPHP and PHPSuexec? My server is Apache, that’s all i know shocked
      • 25663 MODX Staff
      • 12,272 Posts
      You would likely need to talk to your host about adding that.
        Ryan Thrash, MODX Co-Founder
        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
        • 21483
        • 32 Posts
        So suPHP and PHPSuexec is something my host can add to the server?
          • 25663 MODX Staff
          • 12,272 Posts
          That’s correct. It’s a different way they would run PHP.
            Ryan Thrash, MODX Co-Founder
            Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
            • 21483
            • 32 Posts
            Ok, I’ll go ahead and ask them. If they add suPHP and PHPSuexec to the server, but I don’t do the changes suggested in the article, will my site them be unavailable?
              • 21483
              • 32 Posts
              It’s already enabled on my server.

              As soon as I change cache cmod to 700 my site can’t find any articles. If I change some of the other settings then it tell me that I haven’t installed ModX yet.

              Is it because I haven’t installed that patch http://modxcms.com/bugs/?getfile=64 yet, and not applied the changed suggested below the patch location?

              I mean is it necessary to do ALL the changes including the ones in the .php files, and to apply the patch? If yes, how do you apply the patch when you have downloaded it?
                • 21483
                • 32 Posts
                I guess I got to know how to apply/install that suPHP patch. Can you help with that?
                  • 25663 MODX Staff
                  • 12,272 Posts
                  Sorry. I leave the server configuration to the pros that actually have a clue. tongue
                    Ryan Thrash, MODX Co-Founder
                    Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                    • 3188
                    • 75 Posts
                    This is only an issue if you are on a shared server or got more than one user user on the server. As im running my sites on one server under the same linux/unix user, it wouldnt be an issue. Only if someone gets the Root password. (securing windows is a WHOLE other issue! Concerning antivirus, antispyware, antitrojan software to atleast get the illusion of being secure!)

                    Please notice that by running these apache modules, you might get performance issues and perhaps other issues as well.
                    And if the hosting provider have a good sys-admin, it would be concidered fairly unlikely that running without suPHP would be a problem.

                    Although, more and more common is that plugins, modules, snippets and such php code that plugin to CMS, read the password file secretly and send info to another server, or opening room for adding code remotely to the site. Therefore, if you are concerned about server security when you are running a CMS system, make shure that you check thru the PHP code for these type of missuse.

                    I have personaly never seen this on a big CMS community, since these type of missuse are removed instantly when discovered.
                    That however get´s to be a problem with bigger CMS´s like joomla, where there are thousands of 3rd party modules/components.
                    It is also getting more common that the creators protect their PHP code by encrypting it... making it a large security issue.
                      • 21483
                      • 32 Posts
                      Hey beryl

                      "This is only an issue if you are on a shared server or got more than one user user on the server."


                      Well, my host is servage.net, so I guess I’m on a shared server with quite some users? So in my case suPHP would be advisable?