Return-Path: Delivered-To: new-httpd-archive@hyperreal.org Received: (qmail 2174 invoked by uid 6000); 10 Jun 1998 23:42:56 -0000 Received: (qmail 2150 invoked from network); 10 Jun 1998 23:42:53 -0000 Received: from lince.lander.es (qmailr@195.76.46.35) by taz.hyperreal.org with SMTP; 10 Jun 1998 23:42:53 -0000 Received: (qmail 5230 invoked from network); 10 Jun 1998 23:42:47 -0000 Received: from leon.lander.es (195.76.46.38) by lince.lander.es with SMTP; 10 Jun 1998 23:42:47 -0000 Received: (qmail 15323 invoked by uid 1000); 10 Jun 1998 23:42:46 -0000 Date: Thu, 11 Jun 1998 01:42:46 +0200 (CEST) From: Alvaro Martinez Echevarria X-Sender: alvaro@leon.lander.es To: Apache Subject: Re: [PATCH] CGIs not working (PR#2354) In-Reply-To: <19980610164939.A26867@io.com> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=iso-8859-1 Content-Transfer-Encoding: QUOTED-PRINTABLE Sender: new-httpd-owner@apache.org Precedence: bulk Reply-To: new-httpd@apache.org On Wed, 10 Jun 1998, Manoj Kasichainula wrote: > On Wed, Jun 10, 1998 at 11:01:06PM +0200, Alvaro Martinez Echevarria wrot= e: > > -both of the test CGIs are installed without execute permissions > > by "make install", so if you want to use them you need to > > manually do chmod. Shouldn't the installation do that? >=20 > Although I don't know if this was the reasoning, it is probably not a > good idea to enable any preinstalled CGI scripts by default, because > it could lead to problems like the old phf bugs if security holes are > found. If webmasters have to explicitly enable these scripts (which > are only useful for testing anyway), they are much more likely to > disable them when holes are found. On the default configuration CGIs will not be enabled just by setting execute permission, because the ScriptAlias directive is commented out in srm.conf and src.conf.default. The problem comes out if you set it up to allow CGIs: it won't work until you don't chmod (and that's not documented anywhere, I think). Regards. =2E------------------------------------------------------------------. | Alvaro Mart=EDnez Echevarr=EDa | LANDER SISTEMAS | | alvaro@lander.es | P=BA Castellana, 121 | `--------------------------------| 28046 Madrid, SPAIN | | Tel: +34-91-5562883 | | Fax: +34-91-5563001 | `---------------------------------'