DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2008-08-04 17:03:31

dweezil
Member
Registered: 2008-01-26
Posts: 18

Lighttpd and security

Hi Everyone,

I'm wondering about the level of security I need to run lighttpd with an access outside my network (i.e. the Internet).  I'm really concerned about keeping my data away from the internet.

For now, I am running lighttpd as a nobody user (no root rights, shell pointing to /bin/false).

I was thinking about chrooting the lighttpd installation on top of that.  Is it too much?

Thanks.


---------------------------------------------------------------
I have a message to deliver to the cute people of the world...if you're
cute, or maybe you're beautiful...there's MORE OF US UGLY MOTHERFUCKERS
OUT THERE THAN YOU ARE!! So watch out.  -- Frank Zappa

Offline

 

#2 2008-08-04 17:48:33

rcblackwell
Member
From: Pickering, ON
Registered: 2008-05-19
Posts: 204
Website

Re: Lighttpd and security

dweezil wrote:

Hi Everyone,

I'm wondering about the level of security I need to run lighttpd with an access outside my network (i.e. the Internet).  I'm really concerned about keeping my data away from the internet.

For now, I am running lighttpd as a nobody user (no root rights, shell pointing to /bin/false).

I was thinking about chrooting the lighttpd installation on top of that.  Is it too much?

Thanks.

Have you seen http://dns323.kood.org/forum/t793-Reque … httpd.html ?


Bob Blackwell
Pickering, ON

Offline

 

#3 2008-08-04 18:28:49

dweezil
Member
Registered: 2008-01-26
Posts: 18

Re: Lighttpd and security

Thanks,

I saw that when I set up my lighttpd a while ago and it helped,  It's just that some stuff I want to use on my
http server uses a few files from the real root system (/proc files for example) and chrooting removes
access to those files (as far as I know).

I am only asking around if running lighttpd as a non-root user is safe enough.

Cheers


---------------------------------------------------------------
I have a message to deliver to the cute people of the world...if you're
cute, or maybe you're beautiful...there's MORE OF US UGLY MOTHERFUCKERS
OUT THERE THAN YOU ARE!! So watch out.  -- Frank Zappa

Offline

 

#4 2008-08-04 19:55:37

fonz
Member / Developer
From: Berlin
Registered: 2007-02-06
Posts: 1716
Website

Re: Lighttpd and security

dweezil wrote:

I am only asking around if running lighttpd as a non-root user is safe enough.

Afaik, most web servers a hacked through flawed scripts. lighttpd is a mature server, as good as any other.

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB