httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Marc Slemko <>
Subject Re: [PATCH] a different approach to setuid scripts
Date Thu, 19 Jun 1997 01:00:37 GMT
On Wed, 18 Jun 1997, Randy Terbush wrote:

> He has chosen the path of setting effective UIDs, which was 
> originally not acceptable. My feelings haven't changed much in that 
> regard. Would someone else like to comment?

Easy to do, lets you do a lot more (like access web pages as
different users, not just run scripts) but it ain't secure.  It
would also probably tend to introduce too many hassles in a 
threaded world, no?

View raw message