httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jim Jagielski <>
Subject Re: FLOCK stuff
Date Tue, 04 Nov 1997 21:40:02 GMT
Dean Gaudet wrote:
> You don't actually need the secret directory.  You can get by with just a
> root owned mode 600 file.  Note that if the parent directories aren't all
> root owned then this isn't safe ... but that's a general problem already
> (with the log files and symlink race condition attacks).

I added the secret directory to add another layer of "security" (Ha!)
to the test.
      Jim Jagielski            |       jaguNET Access Services           |
            "Look at me! I'm wearing a cardboard belt!"

View raw message