httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jim Jagielski <...@jaguNET.com>
Subject Re: FLOCK stuff
Date Tue, 04 Nov 1997 21:40:02 GMT
Dean Gaudet wrote:
> 
> You don't actually need the secret directory.  You can get by with just a
> root owned mode 600 file.  Note that if the parent directories aren't all
> root owned then this isn't safe ... but that's a general problem already
> (with the log files and symlink race condition attacks).
> 

I added the secret directory to add another layer of "security" (Ha!)
to the test.
-- 
====================================================================
      Jim Jagielski            |       jaguNET Access Services
     jim@jaguNET.com           |       http://www.jaguNET.com/
            "Look at me! I'm wearing a cardboard belt!"

Mime
View raw message