Received: (from majordom@localhost) by hyperreal.org (8.8.5/8.8.5) id NAA02571; Sun, 10 Aug 1997 13:45:39 -0700 (PDT) Received: from eastwood.aldigital.algroup.co.uk (eastwood.aldigital.algroup.co.uk [194.128.162.193]) by hyperreal.org (8.8.5/8.8.5) with SMTP id NAA02567 for ; Sun, 10 Aug 1997 13:45:34 -0700 (PDT) Received: from freeby.ben.algroup.co.uk (freeby.ben.algroup.co.uk [193.133.15.6]) by eastwood.aldigital.algroup.co.uk (8.6.12/8.6.12) with ESMTP id UAA20736 for ; Sun, 10 Aug 1997 20:45:18 GMT Received: from naughty (naughty.ben.algroup.co.uk [193.133.15.107]) by freeby.ben.algroup.co.uk (8.6.12/8.6.12) with ESMTP id VAA12443 for ; Sun, 10 Aug 1997 21:45:12 +0100 Message-ID: <33EE2845.4AF881E8@algroup.co.uk> Date: Sun, 10 Aug 1997 21:44:53 +0100 From: Ben Laurie Organization: A.L. Digital Ltd. X-Mailer: Mozilla 4.01 [en] (WinNT; I) MIME-Version: 1.0 To: new-httpd@apache.org Subject: Re: apachen Configure X-Priority: 3 (Normal) References: <199708102033.QAA28801@devsys.jaguNET.com> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: new-httpd-owner@apache.org Precedence: bulk Reply-To: new-httpd@apache.org Jim Jagielski wrote: > > Anyone else a bit nervous about the format in apachen that all > lines between ConfigStart and ConfigEnd are implicitely trusted? > After all, these are run by and as the person running Configure > and are not limited to Configure-type stuff...?? Hold on - the guy compiling the module is already doing something far more dangerous - admitting C that will run on their system. Caveat emptor. I wouldn't worry about it. Might be worth giving prominent notice that modules can do things at Configure-time, though. Don't just compile it, and _then_ see if it scares you! OTOH, you could do something like "mod_dbm.c wants me to run this: ..., should I or shouldn't I?". Cheers, Ben. -- Ben Laurie |Phone: +44 (181) 994 6435|Apache Group member Freelance Consultant |Fax: +44 (181) 994 6472|http://www.apache.org and Technical Director|Email: ben@algroup.co.uk |Apache-SSL author A.L. Digital Ltd, |http://www.algroup.co.uk/Apache-SSL London, England. |"Apache: TDG" http://www.ora.com/catalog/apache