Hacker News new | past | comments | ask | show | jobs | submit login

For mod_php, they'd run as the same httpd user account and could mess with other user's stuff if they were set to be httpd writeable.

Other isolation levels were needed, like an MPM that would run vhosts as their own user, or a vhost level chroot.

Alternatively, there was php-cgi via suexec, but it didn't have the persistent qualities of mod_php.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: