Re: More security problems in Apache on Mac OS X

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



* Paul Lieberman <lieb@sou.edu> [2001-09-11 16:46:59]:
> This matches any file that starts with a period and seems to do the
> trick. I can't think of an instance where you'd want a hidden file
> to display on the web. Am I missing something?

Yes; I block all dot files by default on my webservers, and ran into a
recent problem where a particular site used Server Side Includes (SSI)
to reference ".lastupdate" files via "#include virtual" statements.
The site stopped working when moved under my webserver, due to the SSI
invoking a full lookup on the URI, which was blocked due to the
dot-file restriction.

Just something to keep in mind...

-- 
Jeremy Mates                                      http://www.sial.org/

	   "You cannot control, only catch." -- Tsung Tsai

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux