Security question about hosting multple websites at ~/Sites

Hi All, I wish to host multiple websites from my server running Mac OS X Server 10.4. I just wanted to know if there are any security risks involved in having sites running from the path ~/Sites. ie /Users/username/Sites/ I am running the machine as a standalone server with port forwarding from my router. Other: Running PHP 4 and MySQL 4 aswell. Is this the wrong way to host sites? If so, do you have any suggestions for other paths that may be more secure? Would it be more secure to host them from the default location /Library/WebServer/Documents? I have FTP set up so that authenticated users see home directory only and have set up users home directories as /Users/username/Sites in the workgroup manager. Is there a better way to set this whole thing up? Am I screwing it from the start? Thanks in advance...

If the user directories are just for hosting sites, the user's won't be using them to store their stuff with an expectations of privacy, there's no inherent insecurity doing it this way. If the users were using their home directories, then it may come as a shock that the read and browse permissions have to be turned on so that the web server can get to the Sites folder to serve pages.
MySQL is a popular database. I would venture to say that most database insecurity is the fault of the DBA, not the database itself.
PHP scripts are listed in the security ezines a lot. I don't know whether PHP is inherently insecure, so simple that people who really don't know how to program can program with it or other reasons.
OSX server isn't an OS I'd trust exposed to the Internet. Apple's done things that make it at least very hard, if not impossible (I haven't really sat down and fought it) to lock it down well.
Roger

Similar Messages

  • TS2446 I forgot the security question about what was my first car and what is my favorite car! What is the solution to change that? please help me, thank you in advance Leo

    I forgot the security question about what was my first car and what is my favorite car! What is the solution to change that? please help me, thank you in advance Leo

    If you have a rescue email address set up on your account then you can try going to https://appleid.apple.com/ and click 'Manage your Apple ID' on the right-hand side of that page and log into your account. Then click on 'Password and Security' on the left-hand side of that page and on the right-hand side you might see an option to send security question reset info to your rescue email address.
    If you don't have a rescue email address set up then go to Express Lane  and select 'iTunes' from the list of 'products' in the middle of the screen.
    Then select 'iTunes Store', and on the next screen select 'Account Management'
    Next choose 'iTunes Store Account Questions' or 'iTunes Store account security' (it appears to vary by country) and fill in that you'd like your security questions/answers reset.
    You should get an email reply within about 24 hours (and check your Spam folder as well as your Inbox)

  • HT5312 HOW TO KNOW THE SECURITY QUESTIONS ABOUT APPLE ID?

    HOW TO KNOW THE SECURITY QUESTIONS ABOUT APPLE ID?HOW TO KNOW THE SECURITY QUESTIONS ABOUT APPLE ID?

    If you have a rescue email address (which is not the same thing as an alternate email address) set up on your account then steps 1 to 5 on the page that you posted from should let you reset them : go to https://appleid.apple.com/ and click 'Manage your Apple ID' on the right-hand side of that page and log into your account, then click on 'Password and Security' on the left-hand side of that page and on the right-hand side you should see an option to send security question reset info to your rescue email address.
    If you don't have a rescue email address (you won't be able to add one until you can answer 2 of your questions) then you won't get the reset option - you will need to contact iTunes Support / Apple to get the questions reset.
    Contacting Apple about account security : http://support.apple.com/kb/HT5699
    When they've been reset (and if you don't already have a rescue email address) you can then use the steps half-way down the page that you posted from to add a rescue email address for potential future use
    For future info typing all in capitals is considered shouting and makes posts difficult to read, and may mean that people don't reply

  • I'm using a new computer and to open one website I have to answer the security questions each time saying that the site doesn't recognize this computer.

    Each time I try to open my "ubt" website, I get a message that says the site does not recognize this computer so I have to answer the security questions each time. I get the message "You are attempting to log in to your account from a computer that we do not recognize..." All other websites work just fine. The Mac store person could not figure it out. This site works on Safari, but I prefer Firefox.

    The ipod is not a backup device. The music sync is one way - computer to ipod.  The only exception is itunes purchases:  Without syncing:File>transfer Purchases
    Copy everything from your backup copy of your  old computer to your new one.

  • How can I get past always ansering my security question for my bacn website.

    I go to my bank website and it always asks me my security question. It also tells me to set my browser settings to recognize the site. How can I change the browser settings if I keep seeing this message. I am using firefox 27.0.1 with windows 7 64 bit. Or am I not able to recognize the site. I understand security is important. I am also using this on my own laptop and home PC.
    Any help would be greatly appreciated

    Such details are stored in a cookie.
    *Create a cookie 'allow' exception to keep such cookies, especially in case of secure websites and when cookies expire when Firefox is closed.
    *Tools > Options > Privacy > Cookies: Exceptions
    In case you are using "Clear history when Firefox closes":
    *do not clear the Cookies
    *do not clear the Site Preferences
    *Tools > Options > Privacy > Firefox will: "Use custom settings for history": [X] "Clear history when Firefox closes" > Settings
    *https://support.mozilla.org/kb/Clear+Recent+History
    Note that clearing "Site Preferences" clears all exceptions for cookies, images, pop-up windows, software installation, passwords, and other website specific data.
    Clearing cookies will remove all specified (selected) cookies including cookies with an allow exception that you would like to keep.

  • HT201209 I cant buy something when input my apple id it ask me some security questions about whats your avorite car?

    I need to know why i cannt buy any game on my apple id

    Forgotten Security Questions/Answers
    You need to contact Apple by:
    1 - Use the Express lane and start here:
    https://expresslane.apple.com
    then click More Products and Services>Apple ID>Other Apple ID Topics>Forgotten Apple ID security questions.
    or
    Apple - Support -form iTunes Store - Contact Us
    2 - Call Apple in your country by getting the number from here:
    http://support.apple.com/kb/HE57
    or           
    Apple ID: Contacting Apple for help with Apple ID account security
    3 - Use your rescue email address if you set one up
    Rescue email address and how to reset Apple ID security questions
    For general  information see:
    Apple ID: All about Apple ID security questions

  • Questions about  hosting and integration of jsp

    hi,
    I have been searching about jsp for a while and i need to ask some question which confuse me.
    First, I have been looking for hosting for jsp but i haven't yet found a useful one.
    And hosting is pretty expensive than php hosting especially in turkey. Do you suggest some international hosting which price is agreable. Also I couldnt find any commercial site (except ibm, java.sun) which is implemented in jsp, if you know some, give some instance.
    Php is much more widespread than jsp. but it still has some disadvantages of being opensource. but lately, I have read an article about sun has started to support php, According to this supprort, can php has an advantage on jsp.

    Dear dudushr,
    This is not at all a pbm.
    what u can do is,
    write ur servlet class and configure that in ur web.xml.(put servlet class in ur WEB-INF/classes dir)
    now in the action part of form tag call the url (just configured in web.xml) for this servlet.
    after executing the query and doing further process within the servlet ,use RequestDispatcher's forward method to pass this values to ur jsp.
    try it and let me know..
    cheers..
    kuttus
    .

  • Security question about opening PDFs in Reader as opposed to Standard or Professional

    Our ITC wants us to open all downloaded PDFs in Acrobat Reader 9 as opposed to Acrobat 7.0 Standard. We currently have both. We download a lot of PDFs and frequently need to Reduce File Size or extract pages, etc. I am hoping to upgrade my Acrobat 7.0 Standard to Professional 9.
    Is there a valid security reason to always open first in Reader? Based on what I have read Acrobat Reader 9 and Professional 9 both had security risks and it is my understanding that a patch has been released today.
    Is there a security risk still for Acrobat Professional 9 and is there a security risk for Acrobat Standard 7.0? Does requiring us to download, save and open PDFs in Reader 9 first make sense from a security standpoint?
    Thanks very much for any input.

    I don't remember any claims that Reader was safer than Acrobat. I use Acrobat exclusively and Adobe recommends against installing both due to conflicts (they use a lot of the same files). The biggest factor to be careful about is to not open any attachments or applications that may be built in. These can be put in the PDF and both Acrobat and Reader open such tools. I would tend to question the basis for the IT folks decision, particularly based on the Adobe recommendation and problems that it creates. At least that is my opinion.

  • DW CS4 Question about Moving Content to New Site

    Hi,
    I'm supposed to meet with a client later about creating a new website and moving all content from the old to the new.  Right now, I have no idea how many pages the old one has.  I'm assuming the worst, which means I'm assuming there will be a lot of pages.
    So after I create a new home page and then a new secondary page, is there some kind of automated procedure Dreamweaver CS4 has that will help me quickly get all of this old content into the new content?  I'm hoping there is because I really want to avoid having to go to each old page, copy the content, and then paste it one by one.  As I think about this, though, if suppose the old site has 100 pages, I guess I'll have to create 100 new secondary pages, then somehow get the content of each of these 100 pages into the new 100 pages.
    Any help is appreciated.

    I agree.  I'm thinking it will probably be easier to start from the ground up.  My biggest fear is it will be 5,000 or 10,000 pages.  And from what I understand (I'll get more specifics at the meeting) the job must be done by 10/27/10, which leaves precious little time.
    I'm meeting with the client this week so as of right now, they cannot show me the existing site until the meeting.
    Mike
    designerandpublisher.com

  • Question about host and local machine and applet

    hello,
    I have a question. I'm writing an applet program that will write a specific file in its working directory in the host machine.
    1)How can i get the working directory of the applet?
    2)How should i specify the path for writing on a file in the applet directory?

    >
    Can an applet write a text file to its own path in the server(or in a folder in its own path)>No. Or at least, not without help from the server.

  • Question about hosting - Flex/Coldfusion

    I'm wanting to use Flex to display Coldfusion info.
    just went through the tutorial at http://www.adobe.com/devnet/flex/articles/fcf_getting_started_coldfusion_flex_02.html and I got the example to work on my local machine. I was also able to do the same with my own data. But the example uses remoting services and I don't know what my hosting providers have on their servers.
    I'm using CrystalTech.com, which is an Adobe partner. But they said they didn't offer Flash remoting on their shared servers.
    I'm not sure if Flash remoting is what I need to get Flash to access the cfc's.
    Can someone tell me if I need to switch hosts (which would be a real pain) and look for a host that has Flash remoting or if that is even what I need?
    Thanks,
    Richie

    A bit odd.. I haven't come across any shared hosting with Remoting disabled yet.
    Have you tried accessing the remoting gateway?
    Should be something like:
    http://yourdomain.com/flex2gateway/
    You normally get to see a blank page.
    If remoting is disabled, you should still be able to access Coldfusion CFC's as webservices.
    To achieve this, simply add "?wsdl" to the url of the cfc - without the quotes.
    Here's an example:
    http://muzakdeezign.com/services/be/pylos/site/NewsSelect.cfc?wsdl
    In Flex you access them using a WebService tag instead of a RemoteObject tag.

  • Basic questions about hosting

    hi everyone, i hope i am posting in the correct forum...
    i have just finished a website (designed with dreamweaver) and i am ready to upload it online. the website is very simple (html), has no flash or animations, only pictures and has a total 50MB worth of files.
    i am having many troubles deciding how to book a suitable hosting and monthly traffic for the website. I hear that 1GB monthly traffic limit might be enough. I don´t know how this exactly works but what i think is that if someone visits the website and checks every single picture, is that already 50MB traffic just from that one visit??
    plus, i am overload with options from different hosting providers and it´s very hard to know which are over priced and which are the most reliable ones. it´d be great to know from other people´s experience which are the best providers.

    Hi--
    I don´t know how this exactly works but what
    i think is that if someone visits the website and
    checks every single picture, is that already 50MB
    traffic just from that one visit??
    Yes, that's pretty much right. It might be somewhat less than 50MB, though. Some website elements, like your style sheet, might be cached by the visitor. In that case, they might only load once per visit, reducing the traffic counted against you.
    charlie

  • Quick question about BIS - Allowed websites

    Hi,
    I would like to know if all web browsing is free with the BIS or is this limited to social websites like facebook etc.
    if there is some kind of list, would someone be able to provide me with such list. Because I don't want to go and browse the internet like a worm and get a huge data charge at the end of the month.
    If someone could clarify this for me I would very much appreciate it.
    Regards,
    Hendrik Wiese

    Hello,
    All of your wireless services are provided by and controlled by your wireless service provider. What is "free" and what will be extra charge is dependent on the level of service contract you have with them. Only they can answer your question.
    Good luck!
    Occam's Razor nearly always applies when troubleshooting technology issues!
    If anyone has been helpful to you, please show your appreciation by clicking the button inside of their post. Please click here and read, along with the threads to which it links, for helpful information to guide you as you proceed. I always recommend that you treat your BlackBerry like any other computing device, including using a regular backup schedule...click here for an article with instructions.
    Join our BBM Channels
    BSCF General Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • Basic question about part-flash websites

    Okay, so really basic stupid question:
    If I'm making an html-based site with flash elements (like a
    table of contents, header, etc), then how do I avoid having to
    reload the movie every time I go to a new page? Ie, if I have a
    flash contents bar, then won't the user have to click to restart
    the movie in order to go to a new link every time it loads, which
    would translate to every new page that the file is embedded into?
    I know I must be missing something obvious, but I'm not sure
    what it is :-) I'm working with a template that does this right
    now, and it's really annoying-- how do well put together sites deal
    with this question?
    Thanks!

    have the buttons load the page into a frame, so the page
    doesn't need to 'refresh'.
    EX:
    my_btn.onRelease = function(){
    getURL("myContentPage.html", "myContentFrame");
    my_btn2.onRelease = function(){
    getURL("myHomePage.html", "myHomeFrame");
    and so on...

  • A few questions about styling my website...

    Hi guys, im very close to finishing my first ever website and i couldnt have done it without the help ive recieved on this forum (especially Nancy.O and Murray ACP)
    Im just trying to tidy up a few bits and pieces now.
    1. Im able to change my fonts using CSS in dreamweaver but when i preview them they havent change. I need the font of the page titles to be 'Futura Condensed Medium' and all other content 'Geneva CY'.
    2. I was hoping for a bigger facebook 'like box', is there such thing as one? i can only find code for that small bar that ive put up on the homepage.
    3. Under Class times 'monday' is stuck as bold and i have no idea how to change it.
    4. Am i able to add a border to the google map i have embeded as i just wanted to add something extra to it.
    Any help would be amazing!
    thanks
    Benn

    1. Im able to change my fonts using CSS in dreamweaver but when i preview them they havent change. I need the font of the page titles to be 'Futura Condensed Medium' and all other content 'Geneva CY'.
    Neither of those are websafe fonts.  Google that term to read about your alternatives.
    2. I was hoping for a bigger facebook 'like box', is there such thing as one? i can only find code for that small bar that ive put up on the homepage.
    Sorry - no idea.
    3. Under Class times 'monday' is stuck as bold and i have no idea how to change it.
    Select those three cells in Design view, and uncheck the "header" checkbox on the Property inspector (note that the cells are <th> not <td>)-
    <tr>
            <th width="73" scope="col">Monday</th>
            <th width="108" scope="col">13.00 -14.15</th>
            <th width="227" scope="col">David LLoyd (members only)</th>
          </tr>
    4. Am i able to add a border to the google map i have embeded as i just wanted to add something extra to it.
    Try changing this -
    <iframe width="380" height="350" frameborder="0" scrolling="no" marginheight="0" marginwidth="0"
    to this -
    <iframe width="380" height="350" frameborder="3" scrolling="no" marginheight="0" marginwidth="0"

Maybe you are looking for