e107 + mod_php = evil
e107 + mod_php = evil
Posted Jan 26, 2010 8:36 UTC (Tue) by efexis (guest, #26355)Parent article: Backdoor in e107 CMS version 0.7.17
It's such a disastrously insecure setup, yet very common, I'm completely amazed by it. Anyone running php virtual hosts out there, I highly recommend mod_fcgid, a rewrite of the earlier fastcgi that runs well and stable and talks to php instances that run under their own UIDs through pipes. In most cases it shouldn't need changes to existing php code, but in some cases it can do, however it's so worth it, php should not be run any other way*.
(*or at all, there's -everything else- out there that's better!)
