httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ben Laurie <...@algroup.co.uk>
Subject Re: apachen Configure
Date Sun, 10 Aug 1997 20:44:53 GMT
Jim Jagielski wrote:
> 
> Anyone else a bit nervous about the format in apachen that all
> lines between ConfigStart and ConfigEnd are implicitely trusted?
> After all, these are run by and as the person running Configure
> and are not limited to Configure-type stuff...??

Hold on - the guy compiling the module is already doing something far
more dangerous - admitting C that will run on their system. Caveat
emptor.

I wouldn't worry about it. Might be worth giving prominent notice that
modules can do things at Configure-time, though. Don't just compile it,
and _then_ see if it scares you!

OTOH, you could do something like "mod_dbm.c wants me to run this: ...,
should I or shouldn't I?".

Cheers,

Ben.

-- 
Ben Laurie            |Phone: +44 (181) 994 6435|Apache Group member
Freelance Consultant  |Fax:   +44 (181) 994 6472|http://www.apache.org
and Technical Director|Email: ben@algroup.co.uk |Apache-SSL author
A.L. Digital Ltd,     |http://www.algroup.co.uk/Apache-SSL
London, England.      |"Apache: TDG" http://www.ora.com/catalog/apache

Mime
View raw message