Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: xampp?
PostPosted: Sat Jun 04, 2005 10:59 pm 
Offline
Senior Newbie

Joined: Tue Jun 01, 2004 6:32 am
Posts: 18
hi,

just wanted to know if anyone tried using xampp?
http://www.apachefriends.org/en/xampp-linux.html

as I needed a quick way to upgrade the Mandrake 9.1's default lamp stack, I chanced upon xampp and tried it out.

so far it rocks out of the box with no compilation for SuSE, RedHat, Mandrake and Debian. php 5.04 (plus eAccelerator -- yummy), apache 2.0.53 (loads of statically compiled in modules), MySQL 4.1.11. when caker comes out with sarge, hope to try it on that as well.

:?: anyone with feedback and care to share on security and best config practice for xampp? I will post stability notes as well...

ttyl
maven


Top
   
 Post subject:
PostPosted: Mon Jun 06, 2005 9:05 am 
Offline
Junior Member

Joined: Thu Apr 21, 2005 12:41 pm
Posts: 43
Website: http://www.jamesl.info
WLM: sipherx@gmail.com
Yahoo Messenger: sipherx598
AOL: sipherx1023
Location: Florida
I went to that link just to check out what xampp was, by the looks of it I wouldnt dare put that on my server, it seems to be very unsecure, and I will show you why.

Here a list of missing security in XAMPP:


The MySQL administrator (root) has no password.
The MySQL daemon is accessible via network.
ProFTPD uses the password "lampp" for user "nobody".
PhpMyAdmin is accessible via network.
Examples are accessible via network.
MySQL and Apache running under the same user (nobody).

Does that sound like something you want anyone to be able to take control over? Especially if your like me and you have a postfix-mysql email server. I would wait until Xampp fixed these issues, also all you people using WebMin there are tons of security issues there as well.

One more thing I just seen Xampp says run the following command:

To fix most of the security weaknesses simply call the following command:

/opt/lampp/lampp security

It starts a small security check and makes your XAMPP installation more secure.

What does "It makes it more secure" mean? lol, I mean give us some specifics, does it password protect stuff or what?

_________________
James Lenhart.


Top
   
 Post subject: help xampp
PostPosted: Mon Jun 06, 2005 10:44 pm 
Offline
Senior Newbie

Joined: Tue Jun 01, 2004 6:32 am
Posts: 18
thx for the comments! but u overreact. no worries. all installations require hardening anyway. have u tested it yet? which was why i asked for testing feedback in the first place. it's kinda new and for development but maybe the devs at xammp could use some of your comments to imprv their sec. join the forum http://www.apachefriends.org/f/?language=english maybe we'll all learn something


Last edited by maven on Mon Jun 06, 2005 10:54 pm, edited 1 time in total.

Top
   
 Post subject: passwords
PostPosted: Mon Jun 06, 2005 10:48 pm 
Offline
Senior Newbie

Joined: Tue Jun 01, 2004 6:32 am
Posts: 18
o forgot to mention, the security script adds password-protects. it's open only initially for quick hacks at your own workstations and then u run the script for server deployment. still trying to find out more...


Top
   
 Post subject:
PostPosted: Wed Jun 08, 2005 10:59 am 
Offline
Junior Member

Joined: Thu Apr 21, 2005 12:41 pm
Posts: 43
Website: http://www.jamesl.info
WLM: sipherx@gmail.com
Yahoo Messenger: sipherx598
AOL: sipherx1023
Location: Florida
Alright, kool I might test it out. Dont think I was flaming you, I wasnt at all.

_________________
James Lenhart.


Top
   
 Post subject:
PostPosted: Wed Jul 27, 2005 9:21 am 
Offline
Senior Newbie
User avatar

Joined: Thu May 12, 2005 4:38 pm
Posts: 9
Website: http://www.mylesbraithwaite.com
WLM: mylesbraithwaite@hotmail.com
Yahoo Messenger: mylesab2002
AOL: MylesAB
Location: Toronto, Ontario, Canada
Sipherx wrote:
To fix most of the security weaknesses simply call the following command:

/opt/lampp/lampp security

It starts a small security check and makes your XAMPP installation more secure.

What does "It makes it more secure" mean? lol, I mean give us some specifics, does it password protect stuff or what?


This will add a root password to mysql and lockup phpMyAdmin and the XAMPP server config.

I have used XAMPP before on an old system running Debian and it worked fine. I havn't tride it on my Linode simply because I use ap-get to grab all the packages.


Top
   
 Post subject:
PostPosted: Sun Jul 31, 2005 1:53 am 
Offline
Senior Member

Joined: Sat Jun 05, 2004 12:49 am
Posts: 333
personaly wouldn't use it.

I use Debian, and installing that would probably throw you into dependency hell


Top
   
 Post subject:
PostPosted: Wed Aug 10, 2005 9:05 am 
Offline
Senior Newbie
User avatar

Joined: Thu May 12, 2005 4:38 pm
Posts: 9
Website: http://www.mylesbraithwaite.com
WLM: mylesbraithwaite@hotmail.com
Yahoo Messenger: mylesab2002
AOL: MylesAB
Location: Toronto, Ontario, Canada
OverlordQ wrote:
installing that would probably throw you into dependency hell


Actually no it work quite while without any dependencies. I recently got it working on a RedHat 7.3 system.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group