httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Rob Hartill <>
Subject Re: my scoreboard file is world writeable
Date Wed, 02 Aug 1995 13:08:38 GMT
> A further thought on scoreboard file security --- one way to fix this
> would be to put the scoreboard file in $(SERVERROOT)/logs by default, or
> at least to allow people to put it there if they wanted.  Permissions on
> that directory could then prevent mischief from the hoi polloi...

Sounds better. It's be useful to have it use the same name *every* time,
so that the files don't pile up (one of our servers has a collection of
old scoreboards in /tmp, and on our HP /tmp doesn't get cleaned up
after a reboot).

> Is this a show-stopper, or can it wait for TNR?

It can certainly wait. It was only by accident that I noticed it.
It's safe from outside attack which is the important thing.


View raw message