I asked a question over at Information Security and received an interesting response which in part included the following:
move them off the server root
So in the context of moving uploaded files "off the server root" I'm not currently sure how to differentiate what directories are and are not owned by the root
user who has access to ... everything?
So how do we define the server root in this context and how can I determine if a directory is not a "server root"?
Bonus points for helpful suggestions in regards to where I should move the files (that are accepted) once they are uploaded.