-
MODX Staff
- 12,272 Posts
You would likely need to talk to your host about adding that.
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
So suPHP and PHPSuexec is something my host can add to the server?
-
MODX Staff
- 12,272 Posts
That’s correct. It’s a different way they would run PHP.
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
Ok, I’ll go ahead and ask them. If they add suPHP and PHPSuexec to the server, but I don’t do the changes suggested in the article, will my site them be unavailable?
I guess I got to know how to apply/install that suPHP patch. Can you help with that?
This is only an issue if you are on a shared server or got more than one user user on the server. As im running my sites on one server under the same linux/unix user, it wouldnt be an issue. Only if someone gets the Root password. (securing windows is a WHOLE other issue! Concerning antivirus, antispyware, antitrojan software to atleast get the illusion of being secure!)
Please notice that by running these apache modules, you might get performance issues and perhaps other issues as well.
And if the hosting provider have a good sys-admin, it would be concidered fairly unlikely that running without suPHP would be a problem.
Although, more and more common is that plugins, modules, snippets and such php code that plugin to CMS, read the password file secretly and send info to another server, or opening room for adding code remotely to the site. Therefore, if you are concerned about server security when you are running a CMS system, make shure that you check thru the PHP code for these type of missuse.
I have personaly never seen this on a big CMS community, since these type of missuse are removed instantly when discovered.
That however get´s to be a problem with bigger CMS´s like joomla, where there are thousands of 3rd party modules/components.
It is also getting more common that the creators protect their PHP code by encrypting it... making it a large security issue.
Hey beryl
"This is only an issue if you are on a shared server or got more than one user user on the server."
Well, my host is servage.net, so I guess I’m on a shared server with quite some users? So in my case suPHP would be advisable?