Re: Hardening Apache against attacks

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> Why .htaccess? Security tip #1 should be 'disable .htaccess'. Performance
> tip #1 too.

I'm not running a vhost clients can control. I'm running a vhost for
production sites my dev team manages, and I don't always want my dev
team restarting Apache to make changes. Also, .htaccess is in version
control (along with all other important app and config files). Aside
from the chance your users will modify .htaccess, why would you
disallow .htaccess? I assume disallowing overrides allows you to set
permissions and behavior in stone. But, it sure makes for a nice tool
to handle redirect changes, new file type restrictions, etc.

--

Jason N

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
   "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx



[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux