List Info

Thread: Severe security problem with eventum.




Severe security problem with eventum.
user name
2006-02-22 22:28:10
Lamont,

> Some of us are wise enough to not AllowOverride. 
That's why I suggested
> using
> <Directory> and/or <Files> tags in the
correct configuration file context
> (with <VirtualHost> for example).

Yeah, that might be true, but _something_ is better than
nothing. Having it
in there might not always make a difference, but the fact
that it will in a
few cases is enough to make it worthwhile.

--Joao


-- 
Eventum Users Mailing List
For list archives: http://lists.mys
ql.com/eventum-users
To unsubscribe:    http:
//lists.mysql.com/eventum-users?unsub=bondyahoo.com

Severe security problem with eventum.
user name
2006-02-22 23:03:11
On Wednesday 22 February 2006 03:28pm, Joao Prado Maia
wrote:
> Lamont,
>
> > Some of us are wise enough to not AllowOverride. 
That's why I suggested
> > using
> > <Directory> and/or <Files> tags in the
correct configuration file context
> > (with <VirtualHost> for example).
>
> Yeah, that might be true, but _something_ is better
than nothing. Having it
> in there might not always make a difference, but the
fact that it will in a
> few cases is enough to make it worthwhile.

You are right.  But there *already is* something there.  The
permissions.php 
file.

But, I think it's not a bad idea to include a sample of how
to better 
configure Apache (and one for lighttpd could be good, too). 
I just do not 
think it's a good idea to include a .htaccess file (a
hidden file, BTW) that 
people may not notice who are less proficient than you and
I.
-- 
Lamont R. Peterson <peregrineopenbrainstem.net>
Founder [ http://blog.
openbrainstem.net/peregrine/ ]
GPG Key fingerprint: 0E35 93C5 4249 49F0 EC7B  4DDD BE46
4732 6460 CCB5
  ___                   ____            _           _
 / _ \ _ __   ___ _ __ | __ ) _ __ __ _(_)_ __  ___| |_ ___
_ __ ___
| | | | '_ \ / _ \ '_ \|  _ \| '__/ _` | | '_ \/
__| __/ _ \ '_ ` _ \
| |_| | |_) |  __/ | | | |_) | | | (_| | | | | \__ \ || 
__/ | | | | |
 \___/| .__/ \___|_| |_|____/|_|  \__,_|_|_|
|_|___/\__\___|_| |_| |_|
      |_|               Intelligent Open Source Software
Engineering
                              [ http://www.OpenBrainste
m.net/ ]
[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )