Uberspace / manual

This manual documents how to use the basic features of Uberspace 7.
https://manual.uberspace.de/
Other
51 stars 108 forks source link

explain security issue on document roots page #491

Open noave opened 1 year ago

noave commented 1 year ago

on https://manual.uberspace.de/web-documentroot/ we write:

We strongly suggest to use different accounts for different projects due to security reasons. If one of the DocumentRoots gets compromised (e.g. because of a CVE), all other files within all other DocumentRoots can be compromised as well.

this sounds like only the doucment roots could be compromised, but more likely your whole uberspace would be compromised (if its not only a very unlikely apache issue which can not see into the home folder)