Current time: 05-21-2012, 04:31 AM Hello There, Guest! (LoginRegister)

Post Reply 
securityw/multiple users and subdomains
01-28-2007, 01:15 PM
Post: #1
securityw/multiple users and subdomains
i just have a quick curious question. i set up a subdomain for a friend of mines with her own user name and all that jazz but i'm worried.
if something ever happens and someone hacks into her site, will they be able to get to my domain and other subdomains or will it just be confined to her own sub?

all user names and pws are completely different.
Find all posts by this user
Quote this message in a reply
01-28-2007, 01:37 PM
Post: #2
securityw/multiple users and subdomains
phew! okay, thank you so so much! i feel so relieved now.
Find all posts by this user
Quote this message in a reply
01-28-2007, 02:27 PM
Post: #3
securityw/multiple users and subdomains
If ALL database directory & user are different,
it's like if your are in dreamhost, and your friend in another host.

Don't forget that DH servers are protected by ninjas, but your scripts may have security hole.

---
Get $97 Off with promo code :97USA Cool choose your plan
Find all posts by this user
Quote this message in a reply
01-28-2007, 02:54 PM
Post: #4
securityw/multiple users and subdomains
But they are protected by Ninjas, right?

(I just can't type that question without laughing after seeing the "Don't do crack" picture on the blog.)

Wholly
Find all posts by this user
Quote this message in a reply
01-28-2007, 03:39 PM
Post: #5
securityw/multiple users and subdomains
Hm.

I believe that, when you create a new user, it's created under the same group. Therefore, if you change the dir to /home/[username]/, as long as it's the same group, I think you'll be able to edit those files. So, it's possible a hacker could pull it off, but they would have to know your username too.

-Kyle

Save $50 on all yearly plans using promo code PHEWSEPHIFTY when you sign up!
Visit this user's website Find all posts by this user
Quote this message in a reply
01-28-2007, 03:43 PM
Post: #6
securityw/multiple users and subdomains
Quote:I think you'll be able to edit those files.
Even if it were true, that would be limited to files that are world-writable. Otherwise we wouldn't need passwords, would we?

--------
Simon's website
Save $100 on 1-year plans with promo code SCJESSEY100 (details)
Visit this user's website Find all posts by this user
Quote this message in a reply
01-28-2007, 03:47 PM
Post: #7
securityw/multiple users and subdomains
Quote:So, it's possible a hacker could pull it off, but they would have to know your username too.
It's easy enough to find user names..just cd up the tree Wink

--rlparker
Find all posts by this user
Quote this message in a reply
01-28-2007, 03:51 PM
Post: #8
securityw/multiple users and subdomains
Quote:It's all about sharing. And it's time (for you) to review permissions...
Well that's a really helpful answer, Bob. Wouldn't it have been easier just to answer my question directly, instead of the cryptic riddle?

--------
Simon's website
Save $100 on 1-year plans with promo code SCJESSEY100 (details)
Visit this user's website Find all posts by this user
Quote this message in a reply
01-28-2007, 04:02 PM
Post: #9
securityw/multiple users and subdomains
Quote:Not for me, seiler.
You have me confused with someone else. I'm scjessey.

--------
Simon's website
Save $100 on 1-year plans with promo code SCJESSEY100 (details)
Visit this user's website Find all posts by this user
Quote this message in a reply
01-28-2007, 04:05 PM
Post: #10
securityw/multiple users and subdomains
Here's the wiki entry:

http://wiki.dreamhost.com/index.php/Unix...y_Defaults

I'll copy-and-paste it here:

When you add a user, it is automatically added to your default pg###### group. Another thing to note is that by default, all of your files are of the same default pg###### group unless you changed it yourself. This means that any other users that you have in the Web Panel have (read) access to all of your files. If you do not trust your users, follow the instructions below.

(It goes on to explain how to ensure that other users can't access your files)

Save $50 on all yearly plans using promo code PHEWSEPHIFTY when you sign up!
Visit this user's website Find all posts by this user
Quote this message in a reply
Post Reply 


Forum Jump: