Web security
Browse around for all files and directories that apache users can access
Lock the range that the php module can access (cage environment)
DocumentRoot / share/1310
ServerName 10.1.1.21
ErrorLog logs/10.1.1.21-error_log
CustomLog logs/10.1.1.21-access_log common
Options Indexes FollowSymLinks
AllowOverride All
Php_admin_value open_basedir "/ share/1310:/var/lib/php/session:/tmp"
Can execute system instructions
# vim / etc/php.ini
Disable_functions = exec,shell_exec,system,passthru,popen
You can delete files that can be deleted by apache users, typically you can delete files in the website directory
You can modify the site page
The valid identity of the httpd process is apache
Suppose the website directory / var/www/html/ root:root 755