Re: Securing handler from direct access via URL.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Jefferson Ogata wrote:

Yes, inasmuch as you didn't clarify that you perceive the configuration as an actual vector for attack, rather than an aesthetically displeasing feature. Instead you mention that it "barfs when accessed directly", which implied to me that you didn't recognize the potential threat.

Opening sentence mentioned chroot'ing.

I wrote was therefore not merely for your benefit, but for that of anyone who comes across this thread in the future.

Fair enough.


--
Regards,
 Daryl Tester

"It's bad enough to have two heads, but it's worse when one's unoccupied."
 -- Scatterbrain, "I'm with Stupid."

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
  "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx



[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux