From owner-freebsd-questions@FreeBSD.ORG Sat Oct 2 21:53:24 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F16AF16A4CE for ; Sat, 2 Oct 2004 21:53:24 +0000 (GMT) Received: from o2.hostbaby.com (o2.hostbaby.com [208.187.29.121]) by mx1.FreeBSD.org (Postfix) with SMTP id B2C7B43D3F for ; Sat, 2 Oct 2004 21:53:24 +0000 (GMT) (envelope-from ceo@l-i-e.com) Received: (qmail 6088 invoked by uid 1001); 2 Oct 2004 21:53:27 -0000 Received: from 66.243.145.38 (SquirrelMail authenticated user ceo@l-i-e.com); by www.l-i-e.com with HTTP; Sat, 2 Oct 2004 14:53:27 -0700 (PDT) Message-ID: <1221.66.243.145.38.1096754007.squirrel@www.l-i-e.com> In-Reply-To: References: Date: Sat, 2 Oct 2004 14:53:27 -0700 (PDT) From: "Richard Lynch" To: "John Oxley" User-Agent: Hostbaby Webmail X-Mailer: Hostbaby Webmail MIME-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 Content-Transfer-Encoding: 8bit X-Priority: 3 (Normal) Importance: Normal cc: freebsd-questions@freebsd.org Subject: Re: Disk quotas X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: ceo@l-i-e.com List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 02 Oct 2004 21:53:25 -0000 John Oxley wrote: > has gallery setup on his webpage and the albums directory is chmod > 707'd so that httpd can write to it. Does that user realize that everybody else on the server can use PHP to write web content to that directory?... Perhaps if a defacement example were demonstrated, he'd move those files out of his web directory, and add in some PHP scripts to read/write the image files with validation-checking, such as using http://php.net/getimagesize to make sure the image file *IS* an image file. > The problem is that httpd creates files as http:group and quota is not > picking up that he is using more disk space than we want him to. One possibility, if you are running Apache 2.0, is to set each PHP user on a directory by directory basis in httpd.conf Or so I've been told. Never done it yet. It cannot (readily) be done in Apache 1.x -- Like Music? http://l-i-e.com/artists.htm