<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: cPanel Apache Security and Optimization</title>
	<atom:link href="http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/</link>
	<description>Did you ever wanted to know more about dedicated servers and web hosting? Here is the place.</description>
	<lastBuildDate>Tue, 06 Mar 2012 13:57:22 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Claudiu Popescu</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-950</link>
		<dc:creator>Claudiu Popescu</dc:creator>
		<pubDate>Sun, 04 Dec 2011 18:40:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-950</guid>
		<description>Hi Chris,

About mod security, I am aware of the fact that installing it won&#039;t help at all.
I did forgot to mention this and to give a few links for mod security rules.

Now about safe mode for php, when I wrote this tutorial I didn&#039;t know very much about safe mode indeed, but I did read the documentation.
At the time, when I used it in production, it was for a server offering free web hosting. You can&#039;t even imagine how many users try to hack into the server using all kind of php scripts. 
Anyway, I stopped using it a long time ago (deprecated since php 5.3 anyway) and I will update my tutorials soon.

Thanks for your comments :)</description>
		<content:encoded><![CDATA[<p>Hi Chris,</p>
<p>About mod security, I am aware of the fact that installing it won&#8217;t help at all.<br />
I did forgot to mention this and to give a few links for mod security rules.</p>
<p>Now about safe mode for php, when I wrote this tutorial I didn&#8217;t know very much about safe mode indeed, but I did read the documentation.<br />
At the time, when I used it in production, it was for a server offering free web hosting. You can&#8217;t even imagine how many users try to hack into the server using all kind of php scripts.<br />
Anyway, I stopped using it a long time ago (deprecated since php 5.3 anyway) and I will update my tutorials soon.</p>
<p>Thanks for your comments <img src='http://www.serverhostingsecrets.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-940</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 12 Oct 2011 06:58:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-940</guid>
		<description>Also, safe mode is useless!

Explanation: If you offer web-hosting, and offer other scripting languages than PHP (such as Perl), if PHP&#039;s safe mode won&#039;t allow vandals into your web presence, they will simply use Perl. If you don&#039;t offer web-hosting, then you don&#039;t need it, as it is supposed to &quot;fix&quot; the shared-server security problem.

Also, safe mode prevents scripts from creating and using directories and files (because they will be owned by the web server, not by the user who uploaded the PHP script). So it&#039;s not only useless, it&#039;s also a hindrance!

It is architecturally incorrect to try to &quot;fix&quot; the shared-server security problem on the PHP level, and you should take measures to fix it on the web-server level. Site-administrators who know what they are doing, know how to do this.

I am sorry to say, but I believe you didn&#039;t know exactly what you were doing when you wrote this tutorial. With all due respect, knowledge comes with experience. ;)</description>
		<content:encoded><![CDATA[<p>Also, safe mode is useless!</p>
<p>Explanation: If you offer web-hosting, and offer other scripting languages than PHP (such as Perl), if PHP&#8217;s safe mode won&#8217;t allow vandals into your web presence, they will simply use Perl. If you don&#8217;t offer web-hosting, then you don&#8217;t need it, as it is supposed to &#8220;fix&#8221; the shared-server security problem.</p>
<p>Also, safe mode prevents scripts from creating and using directories and files (because they will be owned by the web server, not by the user who uploaded the PHP script). So it&#8217;s not only useless, it&#8217;s also a hindrance!</p>
<p>It is architecturally incorrect to try to &#8220;fix&#8221; the shared-server security problem on the PHP level, and you should take measures to fix it on the web-server level. Site-administrators who know what they are doing, know how to do this.</p>
<p>I am sorry to say, but I believe you didn&#8217;t know exactly what you were doing when you wrote this tutorial. With all due respect, knowledge comes with experience. <img src='http://www.serverhostingsecrets.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-939</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 12 Oct 2011 05:57:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-939</guid>
		<description>I hope you know that in order to become really effective, Mod_Security must be configured with rules that help it recognize threats and defend against them. Just &quot;checking it&quot; in EasyApache as you suggest, doesn&#039;t make any sense...</description>
		<content:encoded><![CDATA[<p>I hope you know that in order to become really effective, Mod_Security must be configured with rules that help it recognize threats and defend against them. Just &#8220;checking it&#8221; in EasyApache as you suggest, doesn&#8217;t make any sense&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cPanel Apache Security and Optimization &#124; Vos One</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-933</link>
		<dc:creator>cPanel Apache Security and Optimization &#124; Vos One</dc:creator>
		<pubDate>Fri, 12 Aug 2011 00:47:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-933</guid>
		<description>[...] 1. Navigate to: Main &gt;&gt; Security Center &gt;&gt; Apache mod_userdir Tweak And check: “Enable mod_userdir Protection”  2. Navigate to: Main &gt;&gt; Service Configuration &gt;&gt; Apache Configuration &gt;&gt; Global Configuration Now configure the options as bellow: TraceEnable – Off ServerSignature – Off ServerTokens – ProductOnly FileTag – None MaxClients – 256 MaxRequestsPerChild – 1000 Click “Save” and in the following window click “Rebuild Configuration and Restart Apache”. If you server is under heavy traffic then you should edit: /usr/local/apache/conf/httpd.conf   ? [...]</description>
		<content:encoded><![CDATA[<p>[...] 1. Navigate to: Main &gt;&gt; Security Center &gt;&gt; Apache mod_userdir Tweak And check: “Enable mod_userdir Protection”  2. Navigate to: Main &gt;&gt; Service Configuration &gt;&gt; Apache Configuration &gt;&gt; Global Configuration Now configure the options as bellow: TraceEnable – Off ServerSignature – Off ServerTokens – ProductOnly FileTag – None MaxClients – 256 MaxRequestsPerChild – 1000 Click “Save” and in the following window click “Rebuild Configuration and Restart Apache”. If you server is under heavy traffic then you should edit: /usr/local/apache/conf/httpd.conf   ? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cPanel PHP Optimization / Hardening &#124; Vos One</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-932</link>
		<dc:creator>cPanel PHP Optimization / Hardening &#124; Vos One</dc:creator>
		<pubDate>Fri, 12 Aug 2011 00:44:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-932</guid>
		<description>[...] Before you go ahead with this I strongly recommend reading this article. [...]</description>
		<content:encoded><![CDATA[<p>[...] Before you go ahead with this I strongly recommend reading this article. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudiu Popescu</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-928</link>
		<dc:creator>Claudiu Popescu</dc:creator>
		<pubDate>Mon, 11 Jul 2011 19:14:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-928</guid>
		<description>True, I will update this tutorial soon to reflect recent changes with Apache, cPanel and so on.</description>
		<content:encoded><![CDATA[<p>True, I will update this tutorial soon to reflect recent changes with Apache, cPanel and so on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Server Hardening</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-924</link>
		<dc:creator>Server Hardening</dc:creator>
		<pubDate>Sun, 10 Jul 2011 06:11:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-924</guid>
		<description>Removing apache modules that are not needed could help secure the installation a bit more.  Additionally, fewer mods result in a smaller executable and memory footprint... this means you could run more processes total in limited memory.  My performance testing also resulted in faster performance as well, although not by a very large amount (I think it was 17%).</description>
		<content:encoded><![CDATA[<p>Removing apache modules that are not needed could help secure the installation a bit more.  Additionally, fewer mods result in a smaller executable and memory footprint&#8230; this means you could run more processes total in limited memory.  My performance testing also resulted in faster performance as well, although not by a very large amount (I think it was 17%).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudiu Popescu</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-909</link>
		<dc:creator>Claudiu Popescu</dc:creator>
		<pubDate>Thu, 14 Apr 2011 21:08:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-909</guid>
		<description>@ Solo - At the time I wrote this tutorials I hoped to start a tutorial database for myself and it could help others.
Anyway I didn&#039;t had much time lately.

@Kirsten - By not doing it you risk to get your server overloaded. The guys at cPanel made this script, it reads the memory installed in your server and configures the apache limits accordingly.
By not setting a value for RLimitMEM your server is vulnerable to exploits and badly written scripts.</description>
		<content:encoded><![CDATA[<p>@ Solo &#8211; At the time I wrote this tutorials I hoped to start a tutorial database for myself and it could help others.<br />
Anyway I didn&#8217;t had much time lately.</p>
<p>@Kirsten &#8211; By not doing it you risk to get your server overloaded. The guys at cPanel made this script, it reads the memory installed in your server and configures the apache limits accordingly.<br />
By not setting a value for RLimitMEM your server is vulnerable to exploits and badly written scripts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Solo</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-907</link>
		<dc:creator>Solo</dc:creator>
		<pubDate>Thu, 14 Apr 2011 16:21:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-907</guid>
		<description>I think you should expand your articles (basically all of the tutorials) - and describe WHY you are doing what you&#039;re doing more.  Many things just describe for us to blindly follow you, that&#039;s not really teaching anything...</description>
		<content:encoded><![CDATA[<p>I think you should expand your articles (basically all of the tutorials) &#8211; and describe WHY you are doing what you&#8217;re doing more.  Many things just describe for us to blindly follow you, that&#8217;s not really teaching anything&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kirsten</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-905</link>
		<dc:creator>Kirsten</dc:creator>
		<pubDate>Fri, 08 Apr 2011 15:34:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-905</guid>
		<description>Thanks again for the tips Claudiu.  I had initially found this post while trying to get more info on the memory usage restriction config, because there just wasn&#039;t that much of an explanation in the Apache documentation in regard to the pro &amp; cons.  In your tutorial you recommend it... but why? and what does it actually do? and once you do it, can it be undone if need be?</description>
		<content:encoded><![CDATA[<p>Thanks again for the tips Claudiu.  I had initially found this post while trying to get more info on the memory usage restriction config, because there just wasn&#8217;t that much of an explanation in the Apache documentation in regard to the pro &amp; cons.  In your tutorial you recommend it&#8230; but why? and what does it actually do? and once you do it, can it be undone if need be?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudiu Popescu</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-904</link>
		<dc:creator>Claudiu Popescu</dc:creator>
		<pubDate>Fri, 08 Apr 2011 06:24:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-904</guid>
		<description>Hi Kirsten,

  I suggest switching to Nginx + Apache or LiteSpeed. Apache by its own is not that great for high traffic web sites.</description>
		<content:encoded><![CDATA[<p>Hi Kirsten,</p>
<p>  I suggest switching to Nginx + Apache or LiteSpeed. Apache by its own is not that great for high traffic web sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kirsten</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-903</link>
		<dc:creator>Kirsten</dc:creator>
		<pubDate>Thu, 07 Apr 2011 17:23:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-903</guid>
		<description>Hello Claudiu,

Thanks for posting this info...  I am curous about #3 though.  It seems like it might be a good idea, but what is it actually accomplishing?  And what happens if traffic picks up on a site and it needs more memory allocation than it did at the time the restrictions were set?</description>
		<content:encoded><![CDATA[<p>Hello Claudiu,</p>
<p>Thanks for posting this info&#8230;  I am curous about #3 though.  It seems like it might be a good idea, but what is it actually accomplishing?  And what happens if traffic picks up on a site and it needs more memory allocation than it did at the time the restrictions were set?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudiu Popescu</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-895</link>
		<dc:creator>Claudiu Popescu</dc:creator>
		<pubDate>Fri, 04 Mar 2011 07:53:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-895</guid>
		<description>@John
The latest php 5.2.x is recommended (don&#039;t use an older version since it might have exploits).

@ThinkFast
GD is optional, and indeed needed this days. You must activate the features needed by your web sites, it&#039;s not that easy for a beginner tho.

@Fred
I might write one soon, but I like LiteSpeed so much that I stopped using Apache + FCGID</description>
		<content:encoded><![CDATA[<p>@John<br />
The latest php 5.2.x is recommended (don&#8217;t use an older version since it might have exploits).</p>
<p>@ThinkFast<br />
GD is optional, and indeed needed this days. You must activate the features needed by your web sites, it&#8217;s not that easy for a beginner tho.</p>
<p>@Fred<br />
I might write one soon, but I like LiteSpeed so much that I stopped using Apache + FCGID</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-891</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Thu, 03 Mar 2011 21:22:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-891</guid>
		<description>Thanks! Good info!

When will you do the article about &quot; how to securely configure fcgi as php handler&quot;?

Thank you very much!</description>
		<content:encoded><![CDATA[<p>Thanks! Good info!</p>
<p>When will you do the article about &#8221; how to securely configure fcgi as php handler&#8221;?</p>
<p>Thank you very much!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate Mag</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-848</link>
		<dc:creator>Kate Mag</dc:creator>
		<pubDate>Fri, 18 Feb 2011 14:10:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-848</guid>
		<description>Your article helped me solve my apache/php problem.

Thank you</description>
		<content:encoded><![CDATA[<p>Your article helped me solve my apache/php problem.</p>
<p>Thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ThinkFast</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-794</link>
		<dc:creator>ThinkFast</dc:creator>
		<pubDate>Sat, 05 Feb 2011 23:56:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-794</guid>
		<description>What about GD ?</description>
		<content:encoded><![CDATA[<p>What about GD ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-610</link>
		<dc:creator>John</dc:creator>
		<pubDate>Mon, 20 Dec 2010 11:24:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-610</guid>
		<description>I only had the choice between PHP minor versions PHP 5.2.9 &amp; PHP 5.2.15

I went for PHP 5.2.15
Was that the right way to go?</description>
		<content:encoded><![CDATA[<p>I only had the choice between PHP minor versions PHP 5.2.9 &amp; PHP 5.2.15</p>
<p>I went for PHP 5.2.15<br />
Was that the right way to go?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: server optimization</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-94</link>
		<dc:creator>server optimization</dc:creator>
		<pubDate>Sat, 20 Mar 2010 16:47:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-94</guid>
		<description>[...] Private Server) technologies. Unlike a shared server where everyone shares a pool of server ...cPanel Apache Security and Optimization &#124; Dedicated server ...cPanel comes with apache compiled and configured, but it&#039;s not secure at all, it&#039;s not configured [...]</description>
		<content:encoded><![CDATA[<p>[...] Private Server) technologies. Unlike a shared server where everyone shares a pool of server &#8230;cPanel Apache Security and Optimization | Dedicated server &#8230;cPanel comes with apache compiled and configured, but it&#39;s not secure at all, it&#39;s not configured [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cPanel Apache Security and Optimization &#124; Dedicated server hosting &#8230; &#124; webhostingnew.com</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-76</link>
		<dc:creator>cPanel Apache Security and Optimization &#124; Dedicated server hosting &#8230; &#124; webhostingnew.com</dc:creator>
		<pubDate>Sun, 07 Mar 2010 22:56:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-76</guid>
		<description>[...] this article: cPanel Apache Security and Optimization &#124; Dedicated server hosting &#8230;   Posted in Cpanel Tutorials  Tags: know-more, place, servers-and, the-place-, web hosting, [...]</description>
		<content:encoded><![CDATA[<p>[...] this article: cPanel Apache Security and Optimization | Dedicated server hosting &#8230;   Posted in Cpanel Tutorials  Tags: know-more, place, servers-and, the-place-, web hosting, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudiu Popescu</title>
		<link>http://www.serverhostingsecrets.com/tutorials/securing-apache-cpanel/comment-page-1/#comment-52</link>
		<dc:creator>Claudiu Popescu</dc:creator>
		<pubDate>Wed, 24 Feb 2010 15:06:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.serverhostingsecrets.com/?p=403#comment-52</guid>
		<description>Thank you for the info.
This article was meant only for Apache, I&#039;ll be writing a few more articles that will explain firewalls, linux security and more.</description>
		<content:encoded><![CDATA[<p>Thank you for the info.<br />
This article was meant only for Apache, I&#8217;ll be writing a few more articles that will explain firewalls, linux security and more.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

