Restricting PHP access to server directories

Nick Yaro asked:

Simple question.
Let’s assume in the root folder of my FTP account I have 2 folders: MyDomain.com and FriendsDomain.com.

I have created a separate FTP account for my friend, and made his root path restricted to FriendsDomain.com.

My friend has no access to MyDomain.com from FTP; however, if he uploads a php shell, any file on the account can be accessed.

How can this be prevented?

Thanks!


I answered:

Give the other user his own actual user account.


View the full question and answer on Server Fault.

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.